Do not publish DeepSeek tokens, cookies, HAR files, local logs, .env files, or ~/Library/Application Support/DeepSeekMonitor/credentials.json.
If a token or cookie was accidentally published, revoke the session in DeepSeek immediately and rotate any affected credentials.
Please report security issues privately to the project maintainer. Avoid creating public issues with exploit details, tokens, cookies, account IDs, or HAR attachments.