Lab artifacts are experimental and are not supported production releases. Security reports are still taken seriously because public prototypes can affect downstream designs and may accidentally expose sensitive material.
Do not open a public issue for a vulnerability, credential, private context, proprietary lore, unpublished canon, personal data, or confidential output.
Use GitHub's private vulnerability reporting:
https://github.com/DefinitelySecureStudio/lab/security/advisories/new
Identify the affected experiment or revision, impact, and a synthetic reproduction when possible. Maintainers will coordinate containment, removal of sensitive history when necessary, downstream notification, remediation, and disclosure timing.