Do not open public issues for vulnerabilities. Use GitHub private vulnerability reporting or the repository security contact. Include the affected version, reproduction steps, impact, and mitigation when available. Remove credentials and private data from reports.
Pi Harness is loopback-only by default. Treat profiles, plugins, and executable workspace resources as code.