Use GitHub private vulnerability reporting. Do not include credentials, session cookies, private form content, or exploit details in a public issue.
msforms-api stores its persistent browser profile outside the project:
~/.msforms-api/browser-profile
The package does not intentionally log or return authentication cookies, anti-forgery tokens, or browser storage. Protect the browser profile as you would any signed-in browser profile. Delete it to remove the local session.
Do not commit:
.npmrcfiles containing registry credentials..envfiles.- Browser profiles or storage-state exports.
- Form payloads containing private respondent data.
- Debug logs containing request headers or upload URLs.
Microsoft Forms respondent APIs are reverse-engineered and unsupported. Endpoint behavior and authorization requirements can change without notice. Use least-privilege accounts and review operations before submission.