Use a private GitHub Security Advisory in the agentx-cli Security tab to report a vulnerability. Include the affected version, reproduction steps, impact, and a suggested mitigation. Do not publish credentials or exploit details in a public Issue.
The CLI must never copy API keys, sessions, caches, or authentication files into an AgentX package.