Skip to content

Security: Licentora/awesome-plugins

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this repository — in a plugin, a skill, a manifest, or any code shipped from this marketplace — please do not open a public GitHub issue.

Instead, email support@licentora.com with:

  • A clear description of the issue and its impact.
  • Steps to reproduce (proof-of-concept welcome).
  • The affected plugin, skill, or file path, if applicable.
  • Your name or handle for credit (or "anonymous" if you prefer).

We will respond as soon as we reasonably can. Please give us a fair window to ship a fix before publicly sharing details about the issue.

Scope

In scope:

  • Plugins, skills, and manifests under plugins/ in this repository.
  • Marketplace manifests at the repository root.
  • Repository-level tooling, configuration, and CI.

Out of scope:

  • Third-party plugins or marketplaces referenced or discovered by this marketplace's skills.
  • Vulnerabilities in the host AI agents (Claude Code, Codex, Cursor) themselves — report those to the respective vendors.
  • Social engineering, physical attacks, or denial-of-service against GitHub or Licentora infrastructure.

There aren't any published security advisories