If it could be exploited on a normal, correctly configured install, do not open
a public issue. Report it privately
through GitHub's private vulnerability reporting. A maintainer applies
kind/security only when disclosure is safe.
Public defense-in-depth ideas that are not exploitable vulnerabilities go through the Security hardening issue form instead.
The threat model, trust boundaries, and container-isolation details live in docs/SECURITY.md; the canonical, continuously-verified version is at docs.nanoclaw.dev/concepts/security.