Do not open public issues containing API tokens, MCP bearer tokens, server credentials, database passwords, private logs, or customer data.
For a security report, use GitHub private vulnerability reporting when available. Otherwise contact the repository owner privately.
Keep write capabilities disabled unless needed. Keep destructive access disabled for normal administration. For remote HTTP, use TLS, bearer authentication, and an explicit host allowlist.