If you discover a security vulnerability in OpenSkill, please report it responsibly:
- DO NOT open a public GitHub issue
- Email: security@dnadance.cn (or open a private security advisory on GitHub)
- Include: description, steps to reproduce, impact assessment
- We will respond within 48 hours
OpenSkill is built with security at its core:
- Local-first: All data stored on your filesystem by default
- No telemetry: Zero data sent to any server without explicit opt-in
- Signed assets: Every asset change is signed for audit trail
- Sandbox validation: Imported skills run in isolation before entering the wallet
- Minimal permissions: Each adapter gets only the access it needs
| Version | Supported |
|---|---|
| 0.1.x | ✅ Current |