Report Security Issue
We take the security of Discord bot credentials seriously. If you discover a vulnerability in Diskey, we encourage responsible disclosure and pledge good-faith collaboration.
1. Our Security Commitment
We are committed to maintaining a robust, zero-database security posture. We appreciate the security community helping us keep Discord bot integrations safe.
2. Vulnerability Scope
The following areas are in scope for our vulnerability disclosure program:
- Token leakage, session decryption, or cryptographic bypass in cookie handling.
- Cross-Site Scripting (XSS), Content Security Policy (CSP) bypass, or Server-Side Request Forgery (SSRF).
- Access control bypass or unauthorized API route invocation.
- Service Worker cache poisoning or sensitive data caching.
Out of Scope Issues
- Vulnerabilities within Discord platform infrastructure itself (report directly to Discord Security).
- Volumetric Denial of Service (DoS/DDoS) attacks against hosting infrastructure.
- Social engineering or phishing attempts against maintainers.
- Automated scanner reports without a verifiable proof of concept.
3. How to Report
Please send your vulnerability report directly to ikhlasdigitalhub@gmail.com. Include a detailed description, reproduction steps, proof of concept, and impacted browser environments.
Please do not publicly disclose the issue until a patch has been released and verified.
4. Safe Harbor Policy
We consider research conducted in good faith under these guidelines to be authorized. We will not pursue legal action against researchers who comply with responsible disclosure standards.
5. Suspect Your Bot Token is Leaked?
If you believe your Discord bot token was compromised outside Diskey:
- 1. Immediately go to Discord Developer Portal -> Applications -> Your Bot -> Bot tab.
- 2. Click "Reset Token" to generate a new secret and invalidate the leaked token immediately.
- 3. Review the Discord Server Audit Log for any unauthorized actions executed under your bot identity.