Security Policy

We take the security of Execord and our users seriously. If you discover a vulnerability, please report it privately rather than opening a public issue.

Reporting a Vulnerability

If you find a security bug (such as a way to bypass permissions, bypass token limits, or cause the bot to execute unintended code), please contact us directly via:

Please provide as much detail as possible, including:

Note on Prompt Injection

Basic prompt injection (e.g., tricking the AI into saying inappropriate things or breaking its persona) is an inherent limitation of current Large Language Model technology. These instances are not considered security vulnerabilities unless they lead to unauthorized server modifications.

However, if you find a prompt injection or any other exploit that allows the bot to execute destructive actions without authorization, please report it immediately as a critical security issue.

Responsible Disclosure

We ask that you:

Thank you for helping keep Execord safe for everyone!