Treat all media and analysis results as untrusted. Run decode in resource-limited containers; never accept caller-supplied shell fragments or fetch arbitrary URLs. Model downloads must be pinned and checksum verified with remote Python code disabled. Inference workers must not receive database service keys or provider administration keys. Report vulnerabilities privately to the repository maintainers through the hosting platform's private vulnerability reporting facility when enabled. Do not include customer data in a report.