611 B
611 B
Security
Report TabBot vulnerabilities to [email protected]. Do not attach bot tokens, vault passphrases, or named-secret values.
TabBot does not hold user tokens on HoneyPeer servers. The official origin is https://tab-bot.rest. Vault ciphertext still lives in the visitor’s browser. Typical issues are XSS on a TabBot origin, unsafe module import, or documentation that leaks secrets.
See legal/security.md (also /legal/security) and docs/security/threat-model.md. Incident handling is in the legal Security page.
Hangout: https://join.discord-linux.com. Still do not paste secrets there.