Do not report a suspected vulnerability in a public issue. Use GitHub's private vulnerability reporting for this repository when available, or contact an Atrinik maintainer privately through GitHub.
Reports should include the affected component, a reproducible description, and the smallest safe evidence needed to confirm the issue. Do not include webhook secrets, App private keys, agent private keys, access tokens, join passwords, player data, or host identifiers.