What to include
- Affected component or URL
- Observed behavior and expected behavior
- Security impact
- Minimal reproduction steps
- Your preferred contact information
Do not include student data, credentials, or exploit details in a public channel. Send a concise report to security@courseshelter.com with affected URL/component, impact, and a safe reproduction summary.