If you discover a security vulnerability in this project, please report it privately rather than opening a public issue.
- Preferred: open a private security advisory on GitHub.
- Alternatively, contact the maintainer directly via the email listed on the maintainer's GitHub profile.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof-of-concept if possible.
- Any suggested mitigations you're aware of.
We aim to acknowledge new reports within 7 days and to provide a substantive update on remediation within 30 days.
This project follows a rolling-release model. Only the latest commit on the default branch receives security fixes.
Reports about the skills, prompts, and scripts in this repository are in scope. Third-party services or upstream model providers are out of scope and should be reported to those vendors directly.