HarnessGuard never executes scanned source code. It reads supported text files and parses Python with the standard-library AST module.
Report vulnerabilities through a private GitHub security advisory after publishing the repository. Include the affected version, proof of impact, and a minimal reproducer. Do not include real credentials.
Until version 1.0, only the latest release receives security fixes.