For threat model, bind/API-key rules, and tool toggles, see docs/SECURITY.md.
If you discover a security issue, please report it via your repository’s Security tab (private advisory) or contact the project maintainers directly. Do not file public issues for undisclosed vulnerabilities.