This project is pre-release. Security fixes are applied to the current default branch; no released version line is supported yet.
Do not open a public issue for a suspected vulnerability or include secrets, personal data, or exploit details in public discussion. Use GitHub private vulnerability reporting when it is enabled for the repository. If private reporting is not available, contact the repository owner privately before disclosing details.
Include the affected component, reproduction conditions, impact, and any suggested mitigation. Please allow time for triage and a coordinated fix before public disclosure.
The repository must not contain credentials or identifiable playtest data. First-hours playtests use study-local anonymous IDs, and generated session artifacts remain ignored by Git.