Skip to content

Security: Quavon-dev/CodeCanon-skill

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for a vulnerability that could put users, repositories, credentials, agent environments, or downstream systems at risk.

Report security issues privately to:

rgxdev
hello@d-aaron.dev

Include, when possible:

  • a clear description of the issue;
  • affected files or rules;
  • realistic impact;
  • reproduction steps or an example failure mode;
  • a proposed mitigation, if known.

Please avoid including real secrets, credentials, private repository data, or personal information in reports.

Scope

Security reports may include weaknesses in CodeCanon itself that could encourage unsafe agent behavior, omit an important trust boundary, weaken authorization or validation guidance, or create misleading security guarantees.

Because CodeCanon is instruction-based rather than an enforcement engine, it cannot guarantee that every coding agent will follow every rule correctly. Repository owners remain responsible for reviewing and verifying generated code in their own environment.

Disclosure

Please allow a reasonable opportunity to assess and address a valid vulnerability before public disclosure.

There aren't any published security advisories