Report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue.
Include the output of ski --version, the command, and what happened. Reports are handled on a best-effort basis. Keep the report private until a fix is released.