Please report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue containing credentials, webhook payloads, email content, account identifiers, or exploit details.
This repository must contain only synthetic fixtures. Never commit API keys, OAuth tokens, webhook secrets, connected-account identifiers, real email addresses, or raw provider payloads. Runtime secrets must be injected through environment variables or a secret manager such as 1Password.
Unknown account routes fail closed: events are never written to a default GBrain source.