Please do not report security-sensitive issues through a public GitHub issue.
Send reports privately to:
rgxdev
hello@d-aaron.dev
Include, when available:
- the affected file or workflow;
- the security impact;
- realistic preconditions or attack path;
- reproduction steps or evidence;
- affected versions or commits;
- a suggested mitigation if you have one.
Security reports may include vulnerabilities in:
- CodeInquest's skill instructions that could cause unsafe agent behavior;
- installation guidance;
- prompt-injection resistance or trust-boundary handling;
- audit behavior that could expose secrets or cross security boundaries;
- repository automation maintained by this project.
A missed vulnerability in an unrelated repository audited with CodeInquest is not automatically a vulnerability in CodeInquest itself. Reports should identify a reproducible weakness in CodeInquest's rules, packaging, or maintained automation.
Please allow reasonable time to investigate and address valid reports before public disclosure.