Please report suspected vulnerabilities privately to the repository maintainer rather than opening a public issue with exploit details.
Do not include API keys, OneBot access tokens, bot account credentials, production server addresses, or complete .env files in reports. Revoke and rotate any credential that may have been exposed.