If you discover a security vulnerability within this skill, please report it responsibly.
Do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via email to the maintainers.
Please include the following information in your report:
- Type of vulnerability (e.g., SQL injection, XSS, etc.)
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Only test systems you have authorization to test
- Comply with all applicable laws and regulations
- Follow edu.SRC platform rules
- Do not test prohibited systems (exam, email, OA, academic systems)
- Report vulnerabilities promptly
- Do not publicly disclose vulnerabilities
- Do not download/export real user data
- Do not perform destructive testing
- Use proper isolation when testing
- Control scan speed to avoid DoS
- Use proxy/VPN to protect your identity
- Clean up test artifacts after testing
- Do not store real user data
- Do not exfiltrate sensitive information
- Use test data when possible
- Delete test data after completion
The following activities are strictly prohibited:
- Brute force attacks (including credential stuffing)
- Data exfiltration (downloading/exporting real user data)
- Destructive testing (DoS, data deletion, system damage)
- Testing prohibited systems (exam, email, OA, academic systems)
- Public disclosure of vulnerabilities before修复
- Unauthorized access beyond testing scope
- Confirm target is within edu.SRC scope
- Review platform rules and guidelines
- Set up proper testing environment
- Configure Burp proxy settings
- Use Burp MCP for HTTP operations
- Collect complete evidence (request/response pairs)
- Verify vulnerabilities are real and exploitable
- Avoid unnecessary noise and false positives
- Generate standardized reports
- Review report quality and completeness
- Submit to edu.SRC platform
- Clean up test artifacts
If you encounter a critical security issue:
- Stop testing immediately
- Do not attempt to exploit further
- Report the issue to maintainers
- Provide detailed information about the issue
This security policy will be updated as needed. Please check regularly for changes.
Last updated: 2026-06-10