The bundled audit reads only known public repository surfaces and Git status. It does not read source code, .env, credentials, private Agent transcripts, secret values, plans, backups, or receipts; it does not access the network or change files.
内置审计只读取已知的公开仓库表面和 Git 状态,不读取源代码、.env、凭证、私人 Agent 会话、密钥值、计划、备份或回执;不会联网,也不会修改文件。
Report vulnerabilities through GitHub private vulnerability reporting. Include the version, environment, minimal reproduction, and expected safety boundary without attaching private repository data.
请通过 GitHub 私密漏洞报告 报告漏洞,并提供版本、环境、最小复现和预期安全边界,不要附带私人仓库数据。