Lua TZ assumes that callers, date and time inputs, time zone names, the Lua runtime, and the host time zone database are trusted. It is not designed to isolate mutually untrusted parties or safely process attacker-controlled time zone database files. Applications are responsible for access control, process isolation, time zone database integrity and compatibility, and resource limits. Reports that require a violation of these assumptions are outside the project's security scope, but may still be considered as ordinary robustness or correctness issues.