Spendkit
Responsible disclosure

Security

Please report suspected vulnerabilities privately before public disclosure.

Reporting

Use the repository's GitHub Security page / private vulnerability reporting flow when available:

github.com/jiushi506/Spendkit/security

Do not include private keys, Runtime client secrets, Google session cookies, service-role credentials, or other live secrets in an issue, screenshot, or public discussion.

Useful report details

Do not test with real funds

The current public environment is Arbitrum Sepolia. Security testing should remain non-destructive and should not target third-party wallets, accounts or infrastructure without authorization.