Do not report vulnerabilities in a public issue or discussion.
Email security@midfleet.ai with:
- the affected example or Midfleet surface;
- a minimal reproduction with secrets and customer data removed;
- the expected and observed behavior;
- the potential impact.
Do not include workspace API keys, participant tokens, agent tokens, PATs, deploy keys, provider credentials, delivery signing secrets, private repository URLs, or customer information.