generated: '2026-09-19' method: searched source: SECURITY.md in https://blocklottos.com/git/blocklottos-agent-tools.git (cloned 2026-09-19, HEAD e2f3cb6); probe-security-programs.py 2026-09-19 (vdp=none, trust=none); /.well-known/security.txt 404; /security 404. program: type: security-policy-file channel: support@blocklottos.com statement: '"Report security issues privately to support@blocklottos.com. Do not include private keys, seed phrases, wallet exports, or other credentials."' scope_stated: '"This repository returns unsigned transaction data only. It must never receive private keys or seed phrases, sign transactions, or broadcast wallet transactions."' scope_note: The policy is scoped to the agent-tools repository (MCP server + skill), not declared for the website, the REST API or the smart contracts. It is the only published disclosure channel found. The same address is the OpenAPI info.contact and the agent card contact. safe_harbor: false bug_bounty: null security_txt: false pgp_key: false response_sla: null related: smart_contract_risk_statement: https://blocklottos.com/terms section 6 ("Smart Contract Risk") - a risk disclaimer, not a disclosure program. domain_security: security/blocklottos-com-domain-security.yml pointer_note: 'type: Security and type: VulnerabilityDisclosure both point here. The channel is real and provider-published; its narrow scope is recorded above so the pointer is not read as a site-wide VDP.'