Skip to content

Security: umit/scalesense

Security

SECURITY.md

Security Policy

Supported Versions

ScaleSense provides security fixes for the latest stable release only. Development snapshots and older releases are not supported.

Version Supported
Latest stable release Yes
Older versions and development snapshots No

Report A Vulnerability

Do not open a public issue for a suspected vulnerability. Email umituunal@gmail.com with the subject ScaleSense security report.

Include, when available:

  • The affected ScaleSense version and Codex host/version.
  • A concise impact statement and affected trust boundary.
  • Reproduction steps using non-sensitive sample data.
  • Any proposed mitigation or evidence that the issue is exploitable.

Do not send credentials, secrets, personal data, proprietary source code, or raw private prompts. Redact sensitive values and first ask how to provide any additional material that is genuinely required. Coordinated disclosure is requested while a report is being investigated and fixed.

Release Boundary

ScaleSense v0.2.0 is a skills-only, instruction-only plugin. It contains no MCP server, connector, external endpoint, authentication flow, credential store, hook, bundled executable, telemetry, analytics, or background process. It does not independently transmit data or execute outside the normal Codex host.

The Codex host still processes prompts and selected repository context and may use tools under its configured sandbox and approval policy. ScaleSense does not bypass those controls. Review the package source before installation, pin a known release tag where policy requires it, and apply normal controls to the content supplied to Codex.

Instruction-only packages can still influence model behavior. Reports about prompt-instruction abuse, unsafe recommendations, package integrity, or a path that causes the host to disclose or modify data outside user intent are in scope. General architecture disagreements without a security impact should use GitHub Issues.

There aren't any published security advisories