Please do not open a public issue for a suspected vulnerability or exposed credential. Contact the repository maintainers privately through the security advisory channel enabled for the repository, including a minimal reproduction and impact description. Do not include API keys, Authorization headers, user prompts, responses, or hidden reasoning content.
This project is designed to keep credentials in the NVIDIA_API_KEY process
environment and to report only redacted metadata. It does not perform live
NVIDIA calls unless a user explicitly runs a probe with an already-present
environment variable.
If a credential is committed, revoke or rotate it from a known-clean environment before opening a report.