See the repository security policy.
Use the repository Security page and select Report a vulnerability to submit a private report through GitHub Security Advisories. Do not open a public issue containing vulnerability details or secrets.
The --allow-unsafe-full-access mode intentionally grants explicitly selected
OAuth clients unrestricted filesystem and command access. Report any way for
an unselected or insufficiently scoped client to obtain those capabilities.