Please do not disclose exploitable vulnerabilities in public Issues. Report them through GitHub private vulnerability reporting when enabled, or contact the repository owner through the email listed on their GitHub profile.
Supported security updates currently target the latest minor release on main.
High-priority reports include leaked provider keys, SSRF, authentication/session bypass, exposure of opponents' hands in an online mode, replay privacy failures, billing abuse and unsafe dependency issues. Include reproduction steps and impact, but never include a real secret or another user's data.
The public Demo is currently an offline training game. It is not a secure online competitive room and should not be presented as one.