Skip to content

Security: Mindburn-Labs/distillscan

SECURITY.md

Security

Report suspected vulnerabilities privately to security@mindburn.org. Do not publish vulnerability details in a public issue, pull request, or discussion.

distillscan is an offline command-line tool that parses LLM trace exports and generates workload reports. Reports can cover trace parsing and report generation, including handling of OTLP JSON and Langfuse observations_v2 JSONL.

In your private report, include:

  • The affected release, tag, or commit and your operating environment.
  • A minimal synthetic or redacted trace export, command, and configuration needed to reproduce the behavior.
  • The expected and actual behavior, likely security impact, and any known mitigation.

Remove credentials, personal data, and confidential prompts or outputs from reproductions. Do not submit raw customer traces or production evidence bundles.

There aren't any published security advisories