Please report vulnerabilities through GitHub's private vulnerability reporting feature. Do not include secrets, personal data, or production Ray IDs in public issues.
The security boundary is intentionally small: configuration is local, preview runs in a sandboxed iframe, and exported HTML has no runtime dependency. Reports involving text escaping, unsafe URLs, sandbox escape, or unexpected network requests are especially welcome.