Do not present or export an untrusted deck with execution enabled. check and compile never execute prepared scripts. Review the canonical deck and every referenced file before passing --execute.
Report vulnerabilities privately to the Cortex maintainers. Include the affected version, reproduction steps, impact, and a proposed mitigation if available. Do not include live credentials or sensitive chain keys in the report or fixtures.