Do not open public issues containing Telegram API credentials, bot tokens, phone numbers, session files, private chat IDs, proxy credentials, or runtime databases.
Revoke an exposed bot token through BotFather. Revoke an exposed Telegram user session from Telegram's active-sessions settings and replace the affected API credentials where appropriate.
The repository intentionally excludes every runtime credential and session. Use the private GitHub security-reporting option for source vulnerabilities.