Report vulnerabilities through GitHub Security Advisories. Never post credentials, trust material, private chat, crash state, or production caches.
The client treats network events and resources as hostile: revisions, generations, strings, collections, queues, transfers, expansion, digests, and media types are bounded before commit. Server-selected executable formats, plugins, shaders, and native libraries are forbidden. Credentials, trust, settings, layout, cache, logs, screenshots, and crashes never share a root.
The session remains server-authority preserving: local intent cannot claim gameplay success, hidden state is not reconstructed, and malformed/stale input cannot partially mutate the visible snapshot.