Do not open a public issue for security-sensitive reports.
- Prefer GitHub private vulnerability reporting for this repository (if enabled for the org).
- Otherwise, contact maintainers through the getskillpack org’s coordinated disclosure channel agreed with board (email or security policy at org level).
We aim to acknowledge valid reports within a few business days and to coordinate disclosure before any public details.
This policy covers the getskillpack/cli repository. The registry service and other org repos may have separate contacts; link them from the org-wide policy when it exists.