Do not open a public issue for a suspected vulnerability involving data exposure, authorization bypass, unsafe artifact loading, or release compromise. Use the repository's private GitHub security-advisory reporting flow instead.
Include the connector version, platform, Hermes revision, Antfly Lite build identity, reproduction steps, and whether the report involves an untrusted knowledge artifact. Do not attach private customer documents, credentials, or production databases.
Only the latest tagged connector release is eligible for security fixes. Until the first stable tag exists, all versions are previews and should be evaluated under the boundaries in docs/security.md.