Security

Policy last changed: August 2026

Found something? Report it privately on GitHub (preferred), or email security@llmsecrets.com. First response within 48 hours.

LLM Secrets holds other people's API keys. A flaw in it is their problem as much as ours, so we would rather hear about one from you than from an incident. Finding it is real work, and this page is where the people who do it get named.

Featured researchers

Everyone here found something real in LLM Secrets and told us privately first. Each entry is their name, what they found, and what changed because of it.

No entries published yet.
Reports have come in and are being worked through — entries go up as each reporter approves being named.

What a report earns you

This is an unfunded project, so recognition is the primary reward rather than a consolation for the money. The cash figure is further down and it is small; we would rather you decide with an accurate number than find out afterwards.

Featured highlight A dedicated feature on this page — your name, the finding, and what changed because of it. Not a line in a list.
CVE Requested through a GitHub Security Advisory, formally crediting you. GitHub is a CNA, so the identifier is assigned directly — permanent, indexed in the national vulnerability databases, citable indefinitely.
Advisory credit Your GitHub account in the advisory's structured Credits field, and an invitation onto the draft advisory before it is published.
Hall of Fame A permanent entry in the repository.
Commit credit Co-Authored-By on the commits your report shaped, plus changelog and release-note credit.
Reference A written reference from the maintainer at any point, if it is ever useful to you.

Credit goes up as soon as you approve it — we will not ask you to wait on work that is already done. The published advisory is the one thing that waits, because it only becomes useful to a reader once the fixed build is installable. Anonymity is always available, before, during or after, and choosing it costs you nothing else on this list.

Response timeline

StageTarget
First response48 hours
Triage & severity assessment7 days
Fix for Critical/High14 days
Fix for Medium/Low30 days
Public disclosureAfter the fix is released, coordinated with you

Money

SeverityPayout
Critical$50
High / Medium / LowNo cash payout at this time

That is the real number. This project has no revenue and no security budget, and an earlier version of the policy promised figures it could not honour. Nothing for High is a funding limit, not a signal that High findings are unwelcome — they are among the most useful reports we get, they are fixed on the same timeline as Criticals, and they earn everything in the recognition list above.

Scope

In scope

Out of scope

Full policy

The canonical, authoritative policy is SECURITY.md in the repository — it governs if this page ever disagrees with it. It also covers coordinated disclosure, the 90-day window if we go unresponsive, and our commitment not to pursue legal action against anyone acting in good faith within the policy.

Machine-readable contact details are at /.well-known/security.txt, per RFC 9116.