Do not report vulnerabilities in public issues. Contact the HYGON-AI security or repository-maintainer channel and include the affected skill, version or commit, impact, and a minimal reproduction.
Skills can contain executable scripts and operational instructions. Review source ownership, requested permissions, dependencies, and scripts before installation. Revoke exposed credentials immediately; removing them from Git history is not sufficient.