This repository is a research prototype and is not intended for production or safety-critical deployment.
Please report suspected vulnerabilities privately to
bhuvanrajpoot.codes@gmail.com. Include the affected version, reproduction
steps, potential impact, and any suggested mitigation. Do not publish an
exploit before the maintainer has had a reasonable opportunity to investigate.
Security reports will be acknowledged when received. Supported fixes target the latest released version only; no response-time guarantee is provided.
Only load checkpoints and Hugging Face assets from trusted sources. Project checkpoint reads use weights-only deserialization, model and dataset revisions are pinned, and remote model code is disabled. These controls reduce risk but do not make arbitrary third-party model files safe.
Continuous integration has read-only repository permissions, uses full commit SHAs for third-party actions, and does not persist checkout credentials.
The default dependency set was checked with pip-audit 2.10.1 against PyPI
and OSV on 15 July 2026 with no known advisories. This is a point-in-time
result, not a guarantee; rerun both audits before each release.