Report vulnerabilities privately to the maintainers of the eventual
omdsh-dev/dsh-wecom-plugin repository. Do not include chat content, tokens,
private keys, archive ciphertext, or personally identifiable information in an
issue.
Never commit WeCom credentials, RSA private keys, data/audit keys, actor tokens, or archive data. Authorization, consent, decryption, audit-integrity, and index errors are fail-closed conditions.