Please use GitHub private vulnerability reporting for a security issue. Do not post exploit details in a public issue. You can also contact suboss87@gmail.com.
RAG Scope Check is a test aid, not a security certification. Its result covers only the cases, policy snapshot, and final context IDs supplied to it.