trace-npm observes and reports; it does not contain or sandbox the code it traces. Report vulnerabilities in the tool itself — trace parsing, report generation, secret redaction — privately via GitHub's advisory feature.
You can do this by using the "Report a vulnerability" feature in the "Security" tab of this repository on GitHub. This allows us to discuss and coordinate a fix privately before disclosure.
Please do not open a public issue for security-related bugs.