Useful Security Reports
- Affected package, command or page.
- Reproduction steps.
- Observed output.
- Expected behavior.
- Whether source, generated artifacts or update manifests are involved.
- Whether the issue affects installation, updates, SDK examples, MCP/API behavior or agent instructions.
Documentation Security
Docs issues can be security-relevant when they:- publish unsafe installation instructions;
- expose private infrastructure;
- suggest uploading source where local artifacts should be used;
- overstate release artifact hardening;
- instruct agents to write outside managed sections.

