# Security reporting Do not publish API keys, browser pairing tokens, cookies, raw session records, private prompts or unredacted diagnostic logs in an issue or pull request. If the repository offers GitHub private vulnerability reporting, use that channel for sensitive findings. Otherwise ask the maintainer for a private reporting channel without including exploit details or private data in the public request. No private-reporting feature is assumed to be enabled merely because this file exists. Include the affected plugin/DSH/Node versions, operating system, impact and a minimal synthetic reproduction. The supported runtime is documented in README.md; other versions are not implicitly supported. The plugin operates within DSH's existing authenticated instance and model-routing authority. It does not provide a separate security sandbox or multi-tenant access boundary. See docs/PRIVACY.md for runtime data and reporting precautions.