| Version | Supported |
|---|---|
| 0.4.x | ✅ |
| < 0.4 | ❌ |
Please do not report security vulnerabilities via public GitHub issues.
Report vulnerabilities privately via GitHub Security Advisories.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix (optional)
You will receive a response within 48 hours and a fix within 7 days for critical issues.
Security issues in scope:
- Prompt injection bypass in the
securescanner - Path traversal in skill parsing
- Command injection via hook scripts
- Credential leakage in output/logs
Out of scope:
- Issues in optional dependencies (report upstream)
- Denial of service via large skill files