Please do not open public issues for vulnerabilities that could expose prompts, workspace contents, Claude credentials, or local job output.
Report a vulnerability through GitHub's private vulnerability reporting for this repository. Include reproduction steps, affected versions, and the expected impact when possible.
Claude Ask deliberately exposes no write or shell tools to workspace review jobs. Changes that broaden this boundary should be treated as security-sensitive.