Do not report security vulnerabilities through public issues, discussions, pull requests, or knowledge artifacts.
Use GitHub private vulnerability reporting to send the repository owner a private report. Include:
- A concise description of the vulnerability and its impact
- The affected skill revision or package version
- Reproduction steps using synthetic or redacted data
- Any mitigations you have already identified
Do not include live credentials, private repository URLs, proprietary source code, personal data, or complete unredacted knowledge artifacts. Use minimal placeholders and explain what was redacted.
If GitHub private vulnerability reporting is unavailable, email
adiatwork@outlook.com with the subject
codebase-knowledge-builder security report. Do not open a public issue as a
fallback.
The maintainer will acknowledge a report when it is reviewed, coordinate any necessary disclosure, and credit reporters who request credit when it is safe to do so. Response and remediation timing depends on severity and available maintainer capacity.
Reports may cover the canonical Agent Skill, bundled references and templates, or official package and plugin metadata in this repository. Vulnerabilities in third-party agents, package managers, registries, or target repositories should be reported to their respective maintainers.