Report vulnerabilities privately through GitHub's security advisory interface. Do not open a public issue for a suspected credential, authorization, state-machine, plan-integrity or deployment-boundary vulnerability.
The repository contains no deployment credentials. A reusable workflow or adapter accepting arbitrary shell, runner labels, target selectors or implicit secrets is a security defect.