# Code of Conduct ## Our Pledge In the interest of fostering an open and welcoming environment, we as contributors and maintainers pledge to make participation in our project and our community a harassment-free experience for everyone, regardless of age, body size, disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, religion, or sexual identity and orientation. ## Our Standards Examples of behavior that contributes to creating a positive environment include: * Using welcoming and inclusive language * Being respectful of differing viewpoints and experiences * Gracefully accepting constructive criticism * Focusing on what is best for the community * Showing empathy towards other community members Examples of unacceptable behavior by participants include: * The use of sexualized language or imagery and unwelcome sexual attention or advances * Trolling, insulting/derogatory comments, and personal or political attacks * Public or private harassment * Publishing others' private information, such as a physical or electronic address, without explicit permission * Other conduct which could reasonably be considered inappropriate in a professional setting ## Standards specific to this project Zurp is tooling for Meta bug bounty research. That gives several of the standards above a sharper edge than they have in most projects, and adds a few that are particular to working with live traffic, disclosed findings, and researcher credentials. **Report product vulnerabilities to the bounty program, not to this repository.** A GitHub issue is public from the moment you file it. If you have found a bug in a Meta product — including one you found *using* these tools — it goes through . Issues here are for bugs in Zurp itself: the extension, the MCP servers, the docs. If you are unsure which you have, treat it as a product bug and use the program. **Never put real people's data in this repository.** Not in an issue, a pull request, a commit message, a test fixture, a screenshot or a log excerpt. In practice that means no real account identifiers, names, photos, messages or profile content; no session cookies, `fb_dtsg` values, bearer tokens or other credentials, including your own; and no HAR files or proxy exports you have not read through first. Traffic captures are dense with this material and are the easiest way to leak it by accident. Use test data instead. Building accounts you are allowed to attack is what FBDL is for, and a run's identifiers are safe to share. Where you need to show an identifier's *shape* rather than its value, redact it or invent one — every example in this repository's documentation is fabricated. **Do not republish disclosed findings.** SPARTA leads are disclosed to you personally, under the terms of a private bounty. Reposting one publicly — the title, the summary, the proof of concept, or a description detailed enough to reconstruct it — breaks those terms regardless of whether you meant it as a bug report here. A Zurp bug involving a finding can almost always be described without the finding: its shape, the field that parsed wrong, the error you got. **The maintainers here are not the bounty triage team.** They cannot tell you whether a report is valid, chase a submission, change an award, or explain a triage decision. Issues and pull requests are not an escalation path for any of that, and using them as one is the kind of pressure this document asks you not to apply. **Compete on findings, not on people.** Researchers using this toolkit are often looking at the same endpoints. Disparaging another researcher's work, claiming credit for theirs, or using project spaces to litigate who found what is unacceptable here, whatever its merits elsewhere. ## Our Responsibilities Project maintainers are responsible for clarifying the standards of acceptable behavior and are expected to take appropriate and fair corrective action in response to any instances of unacceptable behavior. Project maintainers have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that are not aligned to this Code of Conduct, or to ban temporarily or permanently any contributor for other behaviors that they deem inappropriate, threatening, offensive, or harmful. ## Scope This Code of Conduct applies within all project spaces, and it also applies when an individual is representing the project or its community in public spaces. Examples of representing a project or community include using an official project e-mail address, posting via an official social media account, or acting as an appointed representative at an online or offline event. Representation of a project may be further defined and clarified by project maintainers. This Code of Conduct also applies outside the project spaces when there is a reasonable belief that an individual's behavior may have a negative impact on the project or its community. It governs the project's own spaces and is separate from the Meta Bug Bounty program terms, which govern your research itself and your dealings with the program. Neither document replaces the other, and conduct that breaches both can be acted on under both. ## Enforcement Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at . All complaints will be reviewed and investigated and will result in a response that is deemed necessary and appropriate to the circumstances. The project team is obligated to maintain confidentiality with regard to the reporter of an incident. Further details of specific enforcement policies may be posted separately. If a report concerns personal data, credentials, or a non-public finding exposed in this repository, say so when you file it: that material is removed first and discussed afterwards. Be aware that anything published to a public repository may already have been cloned, cached or indexed by the time it comes down, so a credential exposed here should be treated as compromised and rotated rather than merely deleted. Project maintainers who do not follow or enforce the Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership. ## Attribution This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, available at https://www.contributor-covenant.org/version/1/4/code-of-conduct.html [homepage]: https://www.contributor-covenant.org For answers to common questions about this code of conduct, see https://www.contributor-covenant.org/faq