If you discover a security vulnerability in this project, report it privately via GitHub Private Vulnerability Reporting.
Please do not report security vulnerabilities through public GitHub issues.
This project has no dedicated security mailbox and no staffed rotation, so timing is best-effort:
we aim to acknowledge a report within 5 business days and give no fixed resolution deadline.
SUPPORT.md defers to this file for vulnerability timing.
In scope: this repository's skill instructions, scripts and published releases. Out of scope: vulnerabilities inside third-party dependencies or host products (report upstream).
| Version | Supported |
|---|---|
| Latest published release | ✅ |
Older tags, and main between releases |
❌ (not covered until released) |