Skip to content

Security: WendongAI/gptskin-skill

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest published GptSkin Skill release. Please update to the newest release before reporting an issue that may already be resolved.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability.

Email support@gptskin.best with the subject Security report and include:

  • the affected GptSkin Skill version and operating system;
  • reproducible steps;
  • the potential impact;
  • any suggested mitigation;
  • whether the issue is already public.

Do not include passwords, API keys, payment credentials, private Codex conversations, or data belonging to another person.

We aim to acknowledge a valid report within 3 business days. We will investigate, coordinate a fix, and agree on a responsible disclosure timeline before public discussion.

Security boundaries

GptSkin applies visual themes locally. It does not read, modify, or transmit Codex conversations. The Skill launches Codex with a loopback-only Chrome DevTools Protocol endpoint while applying a theme. Another process running as the same local user could attempt to connect while that process remains open, so only run the Skill on a trusted machine.

The complete and current security model is published at gptskin.best/docs/security.

GptSkin is an independent product and is not affiliated with or endorsed by OpenAI.

There aren't any published security advisories