- This is a hobby project. Security fixes are best-effort and will generally land on
main.
- Do not open a public issue for security-sensitive reports.
- Email:
security@arnayshukla.com(or DM me on LinkedIn if email bounces).
Include:
- What you found and impact (what an attacker can do)
- Repro steps (requests, payloads, screenshots)
- Any logs/stack traces (redact tokens/PII)
- Leaked API keys / credentials
- Abuse of OpenAI-backed endpoints (cost spikes / DoS)
- Unauthorized access to user resumes (PII)
- This is not intended to meet enterprise compliance requirements.