Please do not open a public issue for a vulnerability that could affect users of the toolkit. Report it privately through GitHub's Report a vulnerability feature on the repository Security tab and include reproduction steps, affected versions, and the expected impact.
The policy engine is a review aid. A missed finding is not, by itself, a toolkit security vulnerability; rule improvements are welcome as regular issues.