# Security Please report vulnerabilities privately to the repository owner. Do not attach sensitive source files to public issues. Imported inputs are untrusted; parsers must remain bounded and must not execute active content or fetch external resources.