Please report suspected vulnerabilities privately to the repository maintainers rather than opening a public issue with sensitive details.
Include the affected version, host adapter, reproduction steps using synthetic values where possible, and whether any raw secret appeared in model-visible content, logs, UI, or audit output.
SecretProtectorAi helps prevent accidental disclosure from supported AI harness tool paths. It is not a guarantee that every secret will be detected or that a host cannot bypass an adapter. Report any path that delivers a detected synthetic secret to a model after the guard says it was blocked.
Never include live credentials in bug reports, fixtures, tests, telemetry, or screenshots.