Please do not report a secret exposure, sealed benchmark leakage, arbitrary code execution vulnerability, or sandbox escape in a public issue. Public reports can expose other users and make evaluation material easier to retrieve.
Use GitHub's private vulnerability reporting feature for this repository when it is available. If that feature is unavailable, open an issue containing only a request to enable private vulnerability reporting, with no vulnerability details, and wait for a private reporting route. GitHub does not provide general private direct messages. Do not include credentials, raw provider responses, private fixtures, or sealed grader material in the report.
For an urgent issue, include the affected release or commit, a concise impact statement, safe reproduction steps, and any mitigation already applied. The maintainers may rotate or remove affected evaluation generations and will coordinate disclosure after the risk is contained. This policy does not guarantee a response time or a particular remediation outcome.