Please do not open a public issue for a suspected vulnerability, exposed credential, authentication bypass, or privacy incident.
Report security concerns privately to support@botnest.app with:
- the affected endpoint or plugin version;
- reproduction steps and impact;
- any relevant logs with credentials and personal data removed.
We will acknowledge the report, investigate it, and coordinate remediation and disclosure when appropriate. Never include Telegram bot tokens, OAuth tokens, LLM API keys, or user data in a GitHub issue.