Azazel-Deception intentionally hosts attacker-facing decoy workloads. Report vulnerabilities that could cross the decoy boundary, bypass Edge authority, weaken egress/production isolation, escape containers, expose real data, forge evidence, or prevent deterministic reset.
Do not include real secrets or production credentials in reports or reference packages.
For public issues, provide only enough information to reproduce safely. For sensitive vulnerabilities, use GitHub's private vulnerability reporting if enabled for this repository.
See docs/safety-model.md for the intended boundary.