CoreSpec follows Semantic Versioning. Only the latest released version (see VERSION and CHANGELOG.md) is actively supported with security fixes.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately using one of these channels:
- GitHub Security Advisories (preferred): open a draft advisory at https://github.com/Htunn/CoreSpec/security/advisories/new.
- Email: contact the maintainer listed on the repository's GitHub profile with a description of the issue, steps to reproduce, and potential impact.
You should receive an acknowledgement within 5 business days. We aim to provide a fix or mitigation plan within 30 days of a confirmed report, depending on severity and complexity.
Please include as much detail as possible:
- A clear description of the vulnerability and its impact
- Steps to reproduce (a proof-of-concept is ideal)
- The affected file(s) — e.g.
install.sh,install-copilot.sh, a specific agent or skill file - Any suggested remediation, if you have one
This project ships two kinds of content, and both are considered in scope for security reports:
- Shell scripts (
install.sh,uninstall.sh,install-copilot.sh,uninstall-copilot.sh) — these run locally with the permissions of the invoking user. Reports of command injection, path traversal, unsafe temp-file handling, or unintended file overwrites are welcome. Scripts are linted with ShellCheck in CI; if you find a pattern ShellCheck misses, please report it. - Agent and skill definitions (
agents/*.md,copilot/skills/*/SKILL.md) — these files are loaded as instructions by AI coding agents (Claude Code, GitHub Copilot). A malicious or compromised change to these files could attempt prompt injection — e.g. instructing an agent to exfiltrate secrets, run destructive commands, or silently alter its behavior. Reports of prompt-injection-capable content, unsafe example commands, or instructions that could cause an agent to take harmful action are welcome and treated as security issues, not just bugs.
- Never commit credentials, tokens, API keys, or
.envfiles. See .gitignore for patterns already excluded. - Keep
set -euo pipefailand quoted variable expansions in all shell scripts; runshellchecklocally before submitting a PR. - Do not add instructions to any agent/skill file that fetch and execute
remote code (e.g.
curl | bash) or that instruct the agent to disable safety checks, hide actions from the user, or exfiltrate data. - Review diffs to
agents/andcopilot/skills/as carefully as you would review executable code — these files directly drive AI agent behavior.