Do not open a public issue for a vulnerability that could enable unauthorized robot control, credential disclosure, or bypass of command/safety gates.
Report security-sensitive findings privately to the Drones Lab maintainers through GitHub's private vulnerability reporting feature for this repository. Include affected revisions, reproduction conditions, impact, and a minimal proof of concept. Do not test against robots or networks you do not own or have explicit permission to operate.
OpenSpot Operator is experimental research software and is not a certified emergency-stop, functional-safety, or cybersecurity system. Maintain an independent stop mechanism and a controlled test area. Never expose the UDP control ports directly to an untrusted network.