Please do not disclose suspected vulnerabilities in a public issue. Use the repository's private vulnerability-reporting channel after the public repository is available, and include reproduction steps, affected files or revisions, required configuration, and potential impact.
OctoNest operates external applications and may handle screenshots, credentials, files, and service data. Treat exposed credentials, cross-account data access, unintended command execution, sandbox escape, and unauthorized external actions as security-sensitive issues.