Please do not create public issues for vulnerabilities. Contact the repository owner privately with a minimal reproduction and enough context to assess impact.
Operational expectations:
- use a high-entropy endpoint secret and rotate it on compromise;
- set ADMIN_TOKEN before exposing the worker endpoint;
- deploy behind authentication, TLS termination, and restrictive egress rules;
- do not point endpoints at private infrastructure unless a reviewed egress policy explicitly permits it;
- redact payloads and endpoint secrets from central logs.