Report a vulnerability privately to the Tank Royale maintainers rather than opening a public issue. Do not include credentials, replay evidence, journal contents, or unpublished bot sources in the report.
The client treats all remote catalog, projection, and submission data as untrusted input. Tokens are supplied only at runtime and must have no repository-content write permission.