Security reports are welcome for:
- Input files being read or written unexpectedly.
- Unsafe handling of output paths.
- Output that leaks data not present in the input.
- Supply-chain or CI issues in this repository.
IOCraft does not need credentials and does not contact external services.
Use GitHub private security advisories when available. Otherwise, open an issue with a minimal synthetic reproduction.