Please do not open a public GitHub issue for security vulnerabilities.
If you discover a security issue — especially anything related to credential handling, token exposure, or data privacy — please report it privately:
- Go to the Security tab of this repo
- Click "Report a vulnerability"
- Fill in the details
We'll acknowledge your report within 48 hours and work on a fix as quickly as possible.
- Bot token exposure or logging
- User data leaking outside localhost
- Path traversal in file output
- CORS misconfiguration allowing external access
- Any vulnerability that could affect a user's Discord account
- Issues caused by users misconfiguring their own
.envor running the app on a public network (the tool is designed for localhost only) - Discord API rate limiting or account issues from high concurrency settings (these are covered in the README warnings)