Do not open a public issue for a suspected credential leak, unsafe hardware-control behavior, or vulnerability that could expose private data. Use the repository's private security-advisory reporting channel.
Include a minimal reproduction, affected version or commit, impact, and any safe mitigation. Do not include secrets, personal paths, screenshots, raw logs, private benchmark data, or copyrighted game content.
Maintainers will acknowledge reports, assess scope, and coordinate a fix before public disclosure where appropriate.