If you discover a security vulnerability in SkillKit, please do not open a public issue. Instead, report it privately so it can be addressed before disclosure.
Please include:
- The affected file(s) and version
- A description of the vulnerability and its impact
- Steps to reproduce (if possible)
We will acknowledge receipt within 3 business days and work on a fix. We ask that you keep the details confidential until a fix is released.
This policy covers the SkillKit hub itself (scripts, manifests, documentation). Each bundled skill pack has its own scope and dependencies; please report issues in the corresponding skill repository.