Report suspected vulnerabilities privately through the affected repository's Security tab or hello@wirecat.dev. Include the repository, version, impact, and a synthetic reproduction. Never send tokens, session files, or private user data. Repository-specific security policies take precedence.