Please report suspected vulnerabilities privately to hello@ausca.com. Include
the affected package and version, a minimal reproduction, and the impact you
observed. Do not include credentials, wallet keys, payment proofs, inbox lease
capabilities, or private user data in a public GitHub issue.
We will acknowledge a usable report and coordinate remediation and disclosure. The public issue tracker is appropriate for ordinary correctness bugs that do not expose data, authority, funds, or service integrity.