Please report leaked credentials, tokens, cookies, personal data, or a vulnerability through the repository host's private security-reporting feature. Do not open a public issue containing sensitive details. If private reporting is unavailable, open a minimal issue asking a maintainer for a private contact channel without including the sensitive material.
Include the affected file or behavior, impact, and a safe reproduction. Redact credentials and user data.
This documentation tracks an unstable, undocumented interface and has no supported-version guarantee. Security-sensitive corrections should be applied to the latest revision.
This project does not operate the Buckler service and cannot fix vulnerabilities in Capcom systems. Suspected vulnerabilities in Capcom services should be reported through Capcom's official security channel, not tested beyond what is necessary to identify the issue.
Never submit:
- authentication cookies, tokens, or copied browser requests containing them;
- techniques for stealing credentials or bypassing access controls;
- raw dumps containing player or account data;
- private browser profile, cookie-store, or session paths.
Rotate any credential immediately if it was exposed, and remove it from published history rather than only deleting it in a later commit.