Skip to content

Security: tomekdot/hermes-skills

Security

SECURITY.md

🔒 Security Policy

Supported Versions

Version Supported
2.x.x ✅ Yes
1.x.x ⚠️ Maintenance only

Reporting a Vulnerability

If you discover a security vulnerability in this project:

  1. Do NOT open a public GitHub issue
  2. Open a GitHub Security Advisory instead
  3. Or contact the maintainer directly

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment

What This Project Does NOT Do

  • Does not collect or store personal user data
  • Does not execute arbitrary code from external sources
  • Does not require elevated system privileges
  • API keys/secrets are stored only as GitHub Secrets, never in code

Dependencies

This project uses minimal third-party dependencies. Review requirements.txt in each skill for details.

There aren't any published security advisories