Please use GitHub Security Advisories for suspected credential exposure, workspace escape, reference-label leakage, or unsafe artifact handling. Do not post secrets or private task content in a public issue.
The default framework copies only an explicit Reviewer allowlist and rejects a formal run directory inside the Git checkout. These controls reduce accidental leakage but do not replace an operator's sandbox, access policy, or data review.