# Security policy ## Reporting a vulnerability Please do not open a public issue for a security vulnerability. Use GitHub's private vulnerability reporting for this repository if it is enabled. If it is unavailable, contact the repository owner through the public contact method on the GitHub profile and include `agent-skills security` in the subject. Include: - The affected skill, file, or release - A clear description of the impact - Reproduction steps or a minimal proof of concept - Any suggested mitigation Do not include credentials, private URLs, or personal data in the report unless they are necessary to reproduce the issue. ## Response You should receive an acknowledgement within seven days. We will investigate, keep the reporter informed when practical, and coordinate disclosure after a fix or mitigation is available. Supported version: the current `main` branch only.