Please report security issues privately to maintainers and avoid public disclosure until fixed.
- Use API tokens with minimal permissions.
- Do not commit credentials or tokens.
- Rotate credentials periodically.
- Enable TLS verification; do not disable in production.