Do not publish exploitable security details in a public issue. Use a private channel approved by the maintainers and include the impact, reproduction steps, minimal sample, affected versions, and suggested remediation.
Include:
- affected skill versions and runtime environments
- reproducible inputs and expected/actual behavior
- whether local files, remote checkouts, or credentials are involved
- mitigations already applied
Maintainers will acknowledge the report and schedule remediation, regression verification, and public communication according to impact. Security fixes must also follow the existing distribution receipt and GitHub release contracts.