Do not open public issues for suspected vulnerabilities. Send a private report
to security@cairo.sh with affected version, impact, reproduction steps, and a
safe proof of concept. We aim to acknowledge reports within two business days.
AGP v0.1 is a draft. The reference HMAC issuer requires an operator-protected key and is not a replacement for managed asymmetric PKI or hardware key custody.