Meta takes the security of our software products and services seriously, including all of the open-source code repositories managed through our GitHub organizations.
If you believe you have found a security vulnerability in SecPriv — including a suppression-rule bypass, a benchmark case that demonstrates a previously-undisclosed code-review evasion, or an issue with the SKILL.md methodology that could mislead reviewers in a security-critical setting — please report it through Meta's security bounty program:
https://www.facebook.com/whitehat
Please do not open a public GitHub issue for security reports.