Security is a core concern of @gottheflag/otp.
Please do not publicly disclose suspected vulnerabilities before they have been reviewed.
Report security issues privately to:
Include the affected version, reproduction steps, expected and observed behavior, and potential impact where possible.
Do not include real OTP secrets, credentials, or other sensitive user data in reports.