Report vulnerabilities privately to jamieparr205@gmail.com. Do not open a public issue for authentication bypasses, setup takeover, stored conversation exposure, context-pack exposure, account blocking failures, provider-key exposure, or session weaknesses.
Do not include live credentials, context packs, exports, or real user conversations in a report. Only the current main branch is supported.