This repository is documentation: Markdown reference modules and three shell scripts. There is no service here to exploit, but a mistake in these docs can lead an AI agent into an unsafe pattern with real keys, so we treat those as security bugs.
Report anything, including security concerns, as a GitHub issue. Include the file and line, what the doc says, and what is actually true, with the curl / source citation if you have one. Email is not a tracked channel and reports sent that way will not receive a response.
For vulnerabilities in the software this skill documents (@proton/cli, @proton/js,
@xpr-agents/*, xpragents.com), report to that project instead: see
XPRNetwork/xpr-agents/SECURITY.md.