The security model (SSRF policy, authentication, key handling, execution isolation) and the vulnerability disclosure policy are documented in docs/SECURITY.md.
To report a vulnerability privately, use GitHub private vulnerability reporting — please do not open a public issue for exploitable findings.