Security fixes are applied to the latest released version and the main branch.
Do not open a public issue for a vulnerability that could expose users, secrets, or systems.
Use GitHub private vulnerability reporting. Include:
- affected version or commit;
- exact file, function, or workflow;
- attacker prerequisites and complete attack path;
- impact and affected assets;
- minimal reproduction using synthetic data;
- suggested remediation, if known.
You should receive an initial acknowledgement within seven days. A coordinated disclosure date will be agreed after validation and remediation planning.
The parser, updater, plugin and skill manifests, packaged scripts, release archives, CI workflows, and documentation that could cause unsafe execution are in scope. Vulnerabilities in third-party services referenced by this project should be reported to their owners.