For a security concern, open an issue requesting a private contact. Keep exploit details out of the public issue.
Security-sensitive areas include CLI file writes, installed agent instructions, dev-only script mounts, and cleanup checks. check and doctor must remain read-only. Keep preview tooling out of production builds and preserve user files when replacing generated assets.