Skip to content

Latest commit

 

History

History
39 lines (25 loc) · 1.23 KB

File metadata and controls

39 lines (25 loc) · 1.23 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use one of these methods:

  1. GitHub Security Advisories (preferred): Report a vulnerability
  2. Email: Send details to the repository owner via their GitHub profile

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

What to Expect

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • Resolution target within 90 days of confirmed vulnerability
  • Coordinated disclosure — we will notify you before any public disclosure
  • Credit in the fix (unless you prefer anonymity)

Scope

This project provides markdown-based skill workflows for AI coding agents. Security concerns most likely involve:

  • Skill workflows that could cause unintended destructive actions
  • Injection risks in templates that get interpolated by agents
  • Information disclosure through skill outputs

Supported Versions

Only the latest release is supported with security updates.