Skip to content

Security: NagisaSano/KpopDoxHunter

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in KpopDoxHunter, please report it privately:

  1. Do NOT open a public issue (to avoid exposing the vulnerability)
  2. Contact me via email: [terunori56100@gmail.com]
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact

I will respond within 48 hours and work on a fix as quickly as possible.

Scope

This is an educational project. Known limitations:

  • Uses YouTube Data API (subject to quota limits and ToS)
  • TF-IDF model is intentionally simple and not production-grade
  • Flask default server is for development only; deploy behind a proper WSGI server if exposed

Responsible Use

This tool is designed for ethical monitoring only. Do not use it to:

  • Harass individuals
  • Distribute private information
  • Violate YouTube's Terms of Service

Thank you for helping keep this project safe!

There aren't any published security advisories