This repository is a Research Preview and has not completed production security qualification.
Use the repository host's private vulnerability-reporting feature. Do not include exploit details in a public issue before maintainers have had a reasonable opportunity to respond.
Include:
- the affected contract or reference module;
- reproduction steps;
- the trust or capability boundary crossed;
- observed and expected behavior;
- a minimal proof when safe to share privately.
The reference implementation demonstrates capability declaration and placement filtering. It does not provide process isolation, secret management, tenant isolation, or hardened remote transport. Treat all reference hosts as educational components.