API Relay Audit is a security project. The standard here is direct technical discussion with enough care that contributors can reproduce, verify, and improve the work.
- Be specific about evidence, commands, versions, and affected files.
- Keep criticism focused on code, documentation, or reproducible behavior.
- Redact API keys, wallet material, private relay traffic, and personal data.
- Assume
inconclusivemeans more investigation is needed, not that someone is wrong or dishonest. - Respect maintainers' scope decisions when a request is outside the project.
- Publishing secrets, credentials, private keys, or non-consensual traffic captures.
- Harassment, personal attacks, or repeated off-topic pressure.
- Using issues or pull requests for relay advertising, brigading, or unsupported safety claims.
- Misrepresenting audit output as a certification.
Maintainers may edit, hide, lock, or remove comments and issues that violate this policy. Severe or repeated violations may lead to a block from the repository.