DearByte runs with macOS Accessibility permission, types into WeChat, and holds a model API key. Please report anything that could let someone else send messages, read chats, get the key, or run code on the Mac.
How to report: use GitHub's private reporting (Security → Report a vulnerability) on this repository. Please don't open a public issue or PR for it.
Leaked secrets: if you spot an API key, a real name or a chat log in the repo or its history, report it the same way, and don't copy it anywhere.
This is a small personal project, so there's no bounty, but reports are read and fixed as soon as possible.