Report security defects privately through the repository host's security advisory channel when available. Do not put raw identifiers, credentials, location history or private captures into public issues. If private reporting is unavailable, contact the repository maintainer to arrange a private channel before sharing.
The root library is inert and does not authenticate devices or authorize physical operations. Exact format recognition does not prove hardware identity. Hosts must explicitly enroll devices, authorize access, protect keys and enforce retention. Never publish raw MAC, IMEI, SIM or location evidence as public Thing identity.