Do not open a public issue containing personal data, credentials or exploitable production details. Report vulnerabilities privately to the project maintainer. Include the affected version, reproduction steps and impact. Rotate any exposed key immediately. The public demo accepts synthetic scenario identifiers only and must not be used for customer data.