If you believe you found a vulnerability in Open Agent Primitives, please report it privately to security@authzed.com. Include the affected version or commit, steps to reproduce, the expected and observed behavior, and any impact you can establish. Do not post exploit details in a public issue before the maintainers have reviewed the report.
The maintainers will acknowledge the report, investigate it, and coordinate a fix and disclosure with affected users.