Please report vulnerabilities privately through GitHub Security Advisories for
kingxiaozhe/zero-workflow. Do not include secrets, private documents, or
personal data in a public issue.
Zero Workflow treats researched content as untrusted input. Reports should not execute embedded instructions, bypass access controls, or upload private local files to third-party services without explicit authority.