Do not open a public issue for a vulnerability or leaked credential.
Report security problems through GitHub's private vulnerability reporting for this repository. Include the affected command, impact, and a minimal reproduction. Do not include live tokens or user data.