SorobanShield is audit-preparation software. Do not use public GitHub issues for a suspected vulnerability in this repository or for sensitive smart-contract source code.
Until a dedicated security contact is published, report repository security concerns privately to the project maintainer through the contact method listed on the repository profile. Include reproduction steps, impact, and a minimal proof of concept where safe to share.
The scanner is heuristic and intentionally conservative. Findings are review prompts, not proof of an exploit. Always use independent expert review before mainnet deployment or handling user funds.