Security
Please report suspected vulnerabilities privately before public disclosure.
Reporting
Use the repository's GitHub Security page / private vulnerability reporting flow when available:
github.com/jiushi506/Spendkit/security
Do not include private keys, Runtime client secrets, Google session cookies, service-role credentials, or other live secrets in an issue, screenshot, or public discussion.
Useful report details
- Affected route, contract function or MCP tool.
- Expected vs observed behavior and a minimal reproduction.
- Whether the issue can cross tenant, Agent, Policy or wallet boundaries.
- Whether a chain transaction is required to reproduce it.
Do not test with real funds
The current public environment is Arbitrum Sepolia. Security testing should remain non-destructive and should not target third-party wallets, accounts or infrastructure without authorization.