Scriptya is a script for local use: it doesn't expose any network service or handle third-party data. Still, if you find a real issue — for example, a way to execute unwanted code through a script's metadata, or a failure in handling paths or permissions — please report it privately instead of opening a public issue.
Write to filonux@proton.me with a description of the problem and, if possible, the steps to reproduce it.
A script that you wrote yourself and placed in your Scripts folder runs with your own permissions, just as if you launched it manually from the terminal. That is expected behavior, not a Scriptya vulnerability.