Report a vulnerability privately through GitHub Security Advisories. Include the file or skill, steps to reproduce, and the impact. Expect a reply within 7 days.
Examples worth reporting: a skill instruction that lets pasted content trigger a publish, a way publish.py could leak cookies, a path that exposes subscriber data.
- Credentials. The bundle ships none.
substack-publisher/scripts/publish.pyis the only file that readsPUBLICATION_URL,COOKIES_STRINGorCOOKIES_PATH, and the only file that imports python-substack.scripts/check_skills.pyenforces this in CI.publish.pyreads credentials only from the environment or~/.substack-skills/.env, never from the current folder. Treat your cookies as a password. - Attended use. The publisher is built to run only while you're present and approving. Substack's Terms of Use prohibit processes that run while you're not logged in. Don't wrap
publish.pyin schedulers or loops. - Untrusted content. Notes, comments, transcripts and exports are data, never instructions. See
references/untrusted-content.md. - Unofficial endpoints. Publishing uses Substack's internal endpoints through python-substack. They're undocumented and can change or be blocked.
- Third parties. Don't test vulnerabilities against Substack outside its own disclosure process.
Only the latest release gets fixes.