Do not publish credentials, private prompts, personal data, proprietary incident details, or exploit material that would create immediate abuse risk.
For sensitive reports, provide only a minimal public description and contact the maintainer privately. Public issues should contain reproducible information that is safe to disclose.