| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in this project, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Email security concerns to: [INSERT EMAIL]
- Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment within 48 hours
- Status update within 5 business days
- Resolution timeline within 14 business days
This security policy covers:
- Skill files that may contain sensitive instructions
- Any scripts or automation in the repository
- Documentation that may expose credentials or secrets
When contributing skills:
- Never include API keys, tokens, or passwords
- Never hardcode credentials in skill files
- Always use placeholder values in examples
- Review your changes for accidental secret exposure before submitting
Security advisories will be published on the GitHub Security Advisories page.