Security disclosure

Report a vulnerability.

If you believe you found a security vulnerability in llibrary, report it privately. The guidance below explains what to send and how to investigate without putting other people or data at risk.

Contact

[email protected]

Send suspected vulnerabilities, reproduction steps, affected URLs, impact, and any safe proof of concept details. Do not include secrets, private user content, or destructive payloads.

Independent testing

Pentest pending

llibrary has not completed its planned third-party penetration test. This page is not a certification, compliance attestation, or statement that an independent audit has been completed.

Safe Harbor

Final terms pending

We intend to support good-faith, non-destructive vulnerability research, but final safe-harbor wording is pending counsel review. Until those terms are published, do not assume this page grants legal safe harbor.

Research guidance

Keep testing non-destructive.

Test only accounts, repositories, and data you own or have explicit permission to use. Do not access other users’ data, degrade the service, use social engineering, or retain exposed data. Do not establish persistence, exfiltrate data, or send spam. Stop once you can demonstrate the vulnerability safely and report it privately.