Do not disclose a suspected SNE vulnerability in a public issue. Use the repository's Security tab and select Report a vulnerability.
Include the SNE version, macOS version, hardware, reproduction steps, expected behavior, observed behavior, and whether the issue reproduces with the package hashes intact. Do not attach model weights or personal prompts.
Only the newest published SNE Technical Preview is eligible for security triage. A Technical Preview does not carry a response-time or remediation SLA.
Security reports may cover the SNE launcher, sealed runtime, packaged dynamic libraries, integrity verifier, and local data handling. Model-provider, GitHub, macOS, MLX, and hardware issues should also be reported to their respective maintainers when appropriate.