Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue containing credentials, tokens, private dataset paths, or an unpatched exploit.
Include the affected commit, operating system, reproduction steps, impact, and any proposed mitigation. You should receive an acknowledgement within seven days. Coordinated disclosure timing will be agreed before publication.
This repository orchestrates third-party evaluation code, model weights, datasets, package managers, WSL, and native tools. Reports about an upstream component may be redirected to that project after the local integration impact is confirmed.