If you discover a security issue in this repository, the hosted service at tokenscanai.com, or in any artifact published by the TokenScanAI organization, please report it privately so we can address it before public disclosure.
GitHub Security Advisory (private): https://github.com/TokenScanAI/tokenapi-scan/security/advisories/new
A clear, minimal report containing:
- What is vulnerable — the URL, endpoint, parameter, or artifact.
- Reproduction — steps a third party can follow to reproduce the issue.
- Impact — what an attacker can do (data exposure, integrity, availability).
- (Optional) Proposed fix — if you have one.
- Issues already documented in public reports or known-issues lists.
- Issues that require a previously compromised browser, OS, or network.
- Vulnerabilities in third-party services we depend on — please report those directly to the upstream maintainer.
- Spam, phishing, or third parties impersonating the service.
- 24 h — acknowledgement.
- 7 d — triage and severity classification.
- 30–90 d — fix + coordinated disclosure (CVE if applicable).
- Threaten legal action for good-faith research conducted under this policy.
- Publish reporter identities without explicit consent.
Disagreements with a detection result on tokenscanai.com are not security issues. Open a GitHub Discussion or contact via the live site. Every detection ships with replayable evidence; if the evidence is wrong, it can be re-tested.
Thanks for keeping TokenAPI Scan honest.