Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting or security-advisory flow in the affected repository. Include:
- the repository and affected version or commit;
- reproduction steps or a minimal proof of concept;
- the expected impact;
- any suggested mitigation.
If the repository does not offer a private reporting channel, contact a Recohut Labs organization owner through GitHub without publishing exploit details.
Experimental status does not make security reports less important. Support and remediation timelines depend on the maturity and maintenance status documented by each repository.