Report vulnerabilities privately through GitHub Security Advisories. Never paste real environment values into a public issue.
Envguard deliberately reports variable names and validation rules, not environment values. It does not decrypt secret stores, expand shell expressions, execute dotenv content, or prove that a credential is valid. Keep environment files out of version control and use a dedicated secret manager in production.