This repository contains OpenCode configuration, prompts, and documentation. It holds no application code, credentials, or secrets.
Do not open a public issue for a suspected vulnerability or leaked credential.
Report it privately through GitHub's private vulnerability reporting on the Security tab of this repository.
If you believe a real credential is present in the repository history, treat it as compromised and rotate it. Do not attempt to scrub it silently; report it so the maintainer can address the history.