Please do not open public issues for vulnerabilities or leaked credentials.
Use GitHub private vulnerability reporting for this repository, or contact the maintainer privately if that option is unavailable. Include a short description, affected version or commit, reproduction steps, and any relevant logs with secrets redacted.
Cog stores Devin credentials in the iOS Keychain and sends API requests directly to Devin. If you believe a credential has been exposed, revoke it in Devin and rotate any affected Apple or GitHub secrets immediately.