Report vulnerabilities privately through GitHub's security-advisory flow. Do not include credentials or non-public Sigil scenarios in an issue.
Released tags and canonical assets are immutable. A defective publication is recovered with a new SemVer, never by replacing or deleting public bytes. This plugin imports no host interface, requests no capability, and holds no ambient authority.