: Never run an obfuscated config. Review the LoliScript or native blocks to ensure they aren't making unexpected outbound calls to Pastebin or GitHub to download unknown binaries.

: Only perform tests on web applications you own or have explicit, written permission to test.

: Third-party versions of OpenBullet may be modified to send your "hits" (successful logins) to the archive creator instead of just your local database.

: Always use a dedicated Virtual Machine (VM) or sandbox environment to protect your primary machine from potential malware.

: These are the "brains" of the tool. A config contains specific instructions on how to interact with a target website, including request headers, parsing rules, and CAPTCHA-solving logic.

: Only use the official OpenBullet GitHub repository.

: Large text files containing "email:password" or "username:password" pairs, often sourced from historical data breaches.