Please do not open a public issue for a vulnerability.
Use GitHub's private reporting: https://github.com/nirholas/vscode-x402/security/advisories/new
You will get an acknowledgement within 3 business days and a status update within 10. Fixes ship as a patch release of @three-ws/vscode-x402 with credit to the reporter unless you prefer otherwise.
In scope: this package's code, its published npm artifact, and its documented configuration. Out of scope: third-party services it talks to, and findings that need a compromised machine or a leaked key.
The latest published minor version of @three-ws/vscode-x402 receives fixes.