Please do not open a public issue for a vulnerability that could expose users, data, credentials, or deployed services. Contact the repository owner privately through the contact method on the maintainer's GitHub profile and include:
- affected commit or release;
- reproduction steps and impact;
- any suggested mitigation; and
- whether you intend to disclose the issue elsewhere.
You should receive an acknowledgement within seven days. No bounty or fixed remediation timeline is promised.
This repository is an experimental benchmark and demonstration API. It has not received a security audit. Users are responsible for authentication, rate limiting, secrets management, dependency review, and network controls before any public or production deployment. Downloaded datasets and model weights are third-party inputs and should be verified according to their source policies.