Report vulnerabilities privately through the repository security advisory process when available.
Default behavior:
- no network requests;
- no telemetry;
- no project code execution;
- no formatter/external command execution unless explicitly configured;
- no shell interpolation for Git acquisition;
- binary and large files summarized rather than parsed.
Debug logs must not include secrets or full file contents by default.