Report security issues privately through GitHub's security-advisory interface. Do not open public issues containing credentials, kubeconfig data, Kubernetes Secrets, private prompts, model weights, internal addresses, or unredacted logs.
The observer intentionally collects a narrow allowlist of fields. Changes that add raw Kubernetes objects or process environments require security review.