Please report suspected vulnerabilities privately through GitHub's Report a vulnerability feature. Do not include live credentials, customer data, or exploit traffic in a public issue.
Security-sensitive behavior should fail closed. A bypass that turns deny into allow, leaks raw tool arguments into the audit log, or permits malformed policy input is considered high severity.