Please report security vulnerabilities through GitHub's private vulnerability reporting feature for this repository. Do not open a public issue or pull request containing exploit details, credentials, private evaluator data, or other sensitive information.
Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Maintainers will acknowledge the report and coordinate disclosure after a fix is available.
Reports concerning the benchmark runner, task isolation, credential handling, private evaluator-data boundaries, or submission verification are in scope. Vulnerabilities in third-party services or datasets should also be reported to their respective maintainers.