Please use GitHub's private vulnerability reporting feature from the repository's Security tab when it is available.
If private reporting is not available, open a public issue asking the maintainer to provide a private contact method, but do not include exploit details, credentials, personal notes, transcripts, or other sensitive data in that issue.
Agent-note stores notes and imported conversations as unencrypted local files. Anyone or any process with access to the configured notes folder can read, change, or delete them. Keep that folder private, apply normal operating-system access controls, and never publish it with the source repository.