This is the organization-wide default. If the repository you're looking at
has its own SECURITY.md, that one applies instead — check there first for
repo-specific supported-version and architecture-scope details.
- Do not open a public issue for a security vulnerability.
- Use GitHub's private security advisory feature on the specific
repository, or email the maintainers directly (see that repo's
MAINTAINERS.md). - Include a clear description, reproduction steps, and the scope of impact.
- Expect acknowledgement within 48 hours.
For the core engine's full security model — sandboxing, data modes, the trust layer — see Wizard-AIA/Wizard-w2's SECURITY.md.