Please do not open public issues for security-sensitive reports.
Instead, report privately to the maintainer with:
- affected environment or commit
- reproduction steps
- impact
- suggested fix if available
Security-sensitive areas include:
- runtime/API key handling
- local command execution boundaries
- leakage of private Mneuma state
- unsafe transcript or memory exposure