If there's a vulnerability within the bot, email me at any of the emails associated with my commits. Especially if it's an important one, I'll keep you posted on resolutions for it as often as possible. I'll also address it in the description of the commit resolving it, and of course credit you for discovery.
If you believe there to be a vulnerability within the bot, test it out to make sure. If it's possibly destructive, let me know first and then test it out on my alt account if applicable.