公開Issueへ脆弱性の詳細、credential、token、private fileを投稿しない。GitHubのSecurity Advisoryから非公開で報告する。
報告には、影響するcollection version、Skill名、再現条件、観測した影響、分かる範囲のsource release identityを含める。秘密情報そのものは含めない。
このrepositoryが扱うのは、catalog、import provenance、配布snapshot、collection install surfaceの問題である。
componentのruntime behavior、対応OS、対応client、system dependency、component固有のsecurity boundaryに関する問題は、該当するcomponent repositoryへ報告する。判断できない場合は、このrepositoryへ非公開で報告してよい。
release inputにはexact commitまたはrelease asset digestを使う。moving branchだけを入力にせず、release済みtagの内容を差し替えない。
catalog sourceは承認済みowner(agent-operated または shinya0x00)に限定する。import前にpublished release、portable path、regular file、公開可能な内容、source容量を検査し、条件に合わない入力はsnapshotへ入れない。