Security issues include defects that could permit false assurance, prompt compromise, identity substitution, covert assistance, evidence fabrication, status or formula fail-open behavior, unauthorized data access, retention failure, or public claims that exceed the evidence.
Report vulnerabilities privately to james.mg@buv.edu.vn with:
- affected version and artifact;
- reproducible conditions;
- likely consequence;
- whether student, staff, institutional, or public claims are at risk;
- a bounded remediation proposal; and
- whether disclosure could enable immediate exploitation.
Do not publish live prompt banks, personal data, credentials, recordings, or step-by-step operational attack recipes. Coordinated disclosure should describe the failure class, affected scope, containment, correction, and requalification without increasing avoidable harm.
The included red-team and validation materials are reference instruments. They do not authorize testing against a live institution, student cohort, or system without explicit permission, ethics/governance review, and applicable legal authority.