Do not open public issues for vulnerabilities.
Use GitHub private vulnerability reporting:
https://github.com/agent-trail/spec/security/advisories/new
Do not include secrets, credentials, private local paths, or unredacted session data in reports unless they are necessary to reproduce the issue.