Report vulnerabilities privately via GitHub Security Advisories.
SignShield runs offline by default — it never sends your transaction to third parties unless you pass --rpc / enable RPC in the extension.
Never paste real private keys. Example fixtures use fake addresses only.
- Example API:
/api/examples/{name}rejects path traversal and non-*.jsonnames. - RPC URLs: only
http/https; loopback HTTP allowed for local nodes; private, link-local, and metadata addresses are rejected before any request.
If you find a bypass, please report it privately before opening a public issue.