CHNAI LAB builds several private product repositories, including education, agriculture, SME operations, cybersecurity, and trading tools. Security issues are handled conservatively because many projects are future startup assets.
Do not publish exploit details, credentials, tokens, private user data, or production infrastructure information in public issues, pull requests, comments, screenshots, or prompts.
For public repositories, use GitHub's private vulnerability reporting or contact a CHNAI LAB owner directly. For private repositories, report the issue in the team's private channel and link the affected repository, commit, route, screen, or workflow.
- Affected repository and area.
- Reproduction steps.
- Expected impact.
- Logs or screenshots with secrets removed.
- Suggested fix if known.
- Confirm the report privately.
- Open a private tracking issue.
- Patch on a branch.
- Verify with tests, manual reproduction, or both.
- Merge through pull request review.
- Rotate any exposed secret and document follow-up work.
AI agents may help investigate and patch security issues, but they must not be given raw secrets, private customer data, or production credentials. Share redacted logs and minimal reproduction context instead.