If you discover a security vulnerability in this repository — in a plugin, a skill, a manifest, or any code shipped from this marketplace — please do not open a public GitHub issue.
Instead, email support@licentora.com with:
- A clear description of the issue and its impact.
- Steps to reproduce (proof-of-concept welcome).
- The affected plugin, skill, or file path, if applicable.
- Your name or handle for credit (or "anonymous" if you prefer).
We will respond as soon as we reasonably can. Please give us a fair window to ship a fix before publicly sharing details about the issue.
In scope:
- Plugins, skills, and manifests under
plugins/in this repository. - Marketplace manifests at the repository root.
- Repository-level tooling, configuration, and CI.
Out of scope:
- Third-party plugins or marketplaces referenced or discovered by this marketplace's skills.
- Vulnerabilities in the host AI agents (Claude Code, Codex, Cursor) themselves — report those to the respective vendors.
- Social engineering, physical attacks, or denial-of-service against GitHub or Licentora infrastructure.