Part of the AAA+ program's C-axis (trust) sweep across the open/ org:
a stated vulnerability-reporting address and response process is what a
stranger evaluating the repo looks for before reading any code.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011WZqVHfRgn26fS6neSMU9v