Skip to content

Security: Xquik-dev/hermes-tweet

Security

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes target the latest published release.

Reporting A Vulnerability

Report vulnerabilities privately by emailing support@xquik.com.

Do not open public issues for secrets, credential handling bugs, private data exposure, account takeover paths, or write-action safety bypasses.

Scope

Security-sensitive areas include:

  • API key handling
  • Action endpoint gating
  • Catalog allowlisting
  • Private X account reads
  • Tweet, delete, follow, DM, profile, monitor, webhook, extraction, and draw actions
  • Package supply chain metadata

There aren't any published security advisories