Version 1 is pre-release until the first public npm package is published. Security fixes target main.
Open a private security advisory on GitHub. If unavailable, open an issue with minimal reproduction details and no exploit payloads.
Include: affected package, expected impact, reproduction steps, and whether the issue requires malicious corpus input, malicious MCP input, or deployment access.