Private disclosure template

Use this only for a vulnerability in a game you are authorized to inspect. Do not include a credential, even partially. Do not test whether it works.

Subject: Private security report: credential/configuration exposed in [game]

Hello [security or development team],

I found [credential class / configuration issue] in a publicly distributed
build of [game and version] using the offline static analyzer Xila. I did not
use the credential or access any service.

Location: [platform and build path; omit secret-bearing source text]
Impact: [what the credential class normally permits, without claiming access]
Recommended immediate action: revoke or rotate the credential. Move privileged
operations to a trusted server and publish an updated build.

I can provide a redacted Xila finding and reproduction steps through a secure
channel. Please acknowledge receipt and suggest a disclosure timeline. I will
not publish details or the credential.

Regards,
[name / contact]

If no security address exists, use the developer's published support channel or the storefront's developer contact. If that fails, contact the platform. See SECURITY.md for Xila's 90-day default and escalation address.