ReproKit is designed to run locally and does not intentionally upload report data or access .env values. Its redaction rules are a safety net, not a guarantee that a generated report is safe to share.
Please do not publish a security vulnerability as a public GitHub issue. Instead, contact the repository owner privately with a minimal description and sanitized proof of concept. Avoid sending secrets, access tokens, private repository URLs or customer data.