RouteInfra is an infrastructure control plane. Please do not disclose unpatched vulnerabilities in public issues.
Until a dedicated security mailbox is published, open a private GitHub security advisory for this repository. Include the affected version, a minimal reproduction, impact, and whether credentials or model data could be exposed. Do not include real prompts, tokens, credentials, private endpoints, or model weights in the report.
Security reports are especially important for signed execution plans, Agent authorization, tenant isolation, receipt tampering, plugin loading, secret handling, and prompt-data persistence. RouteInfra is designed to store prompt digests rather than raw prompts by default, but deployments must still review logs and external engine configuration.