Please do not open a public issue for an unpatched vulnerability.
Use GitHub's private vulnerability reporting or a private contact method available through the maintainer profile. Include the affected file or version, a concise reproduction, impact, and any safe mitigation. Remove secrets, personal data, and production identifiers from the report.
If private reporting is unavailable, open a minimal public issue that only asks the maintainer to establish a private channel; do not disclose exploit details.
This policy covers the skill instructions, helper scripts, templates, and repository automation in this repository. The skill's recommendations are not a security certification; users remain responsible for validating their own systems and dependencies.
The latest commit on the default branch is the supported version. Security fixes may also be backported when a tagged release needs continued support.
The maintainer will coordinate a fix and disclosure timeline with the reporter. Please allow reasonable time for triage and remediation before public disclosure.