Repository navigation
v0.7.1 — CONTRIBUTING.md + SECURITY.md
[0.7.1] - 2026-05-10
Community-health files added — CONTRIBUTING.md and SECURITY.md. No skill changes; these are the files the skills already referenced (pr-review Step 1/Step 6, issue-triage Step 0/Step 1, hotfix-flow, release-sop Step 2). Patch release.
Added
CONTRIBUTING.md— contributor guide — codifies the two hard rules (one skill per directory, ecosystem-agnostic core), what shipping a new skill entails (SKILL.md+examples/<name>-demo.md+ README rows + CHANGELOG entry;install.shauto-discovers), the PR conventionspr-reviewchecks (titletype(scope): summary, What/Why + linked issue, tests/CHANGELOG/docs same-PR, CHANGELOG goes in[Unreleased]not a tag commit — pointer tochangelog-bot, Breaking + migration line, the security flag), local-testing steps (./install.sh <skill>→ restart Claude Code), and the release / hotfix procedure (release-sop/hotfix-flow; tag is the only release trigger;mainis protected, all changes via PR). Previously these rules lived only as a two-line section in the README.SECURITY.md— security policy — supported versions (latest release only; upgrade before reporting), what counts as a security issue for a docs/skill repo (a SKILL.md that could be steered to do harm or skip a gate;install.shfilesystem surprises; supply-chain of the raw-URL install path) vs. an ordinary bug, how to report privately (GitHub private vulnerability reporting via the Security tab — no public issues/PRs/discussions with details or PoCs), what to expect (acknowledgement, fix-or-written-decision,hotfix-flowfor fixes that can't wait, coordinated disclosure with an advisory naming affected versions, credit), and how it ties into the skills (issue-triageroutes here,pr-reviewStep 6 requires this flow,hotfix-flowruns security fixes through it).pr-review,issue-triage,hotfix-flow, andrelease-sopall referenceSECURITY.md; this is the file they were referencing.README.md— Contributing section points toCONTRIBUTING.md/SECURITY.md; layout tree updated — the Contributing section keeps the two-line rule summary and now links the fullCONTRIBUTING.mdandSECURITY.md, plus notesmainis protected; the repo-layout tree gainsCONTRIBUTING.mdandSECURITY.mdrows.