Report suspected vulnerabilities through a private GitHub security advisory, not a public issue or discussion.
Wolfpack provides shell-equivalent access to configured projects. Authentication or authorization bypass, command execution or command injection, path-boundary escapes, secret exposure, and unsafe network-boundary issues are appropriate for private reporting.
Use non-production test data and provide a minimal private report containing the impact, reproduction steps, and affected version. Do not include unrelated private data.
This routing page makes no response SLA, supported-version window, bounty, embargo, disclosure timeline, or severity promise.
For ordinary bugs or usage help, use Support and reporting.