Do not open a public issue for a security problem.
Mail the maintainers at security@tinyhumans.ai with what you found, how to reproduce it, and what you think the impact is. We will confirm receipt and keep you updated.
Never include real secrets, tokens, or customer data in a report. tinysweeper handles untrusted pull request content and mints GitHub write tokens, so reports about prompt injection, token scope, or anything that could cause contributor code to execute are particularly welcome.