Only the latest published npm version is actively maintained.
Please report security issues privately through GitHub Security Advisories when available for the repository:
https://github.com/Dimon94/brainstorming-only/security/advisories/new
If advisories are unavailable, open a GitHub issue with a minimal description and avoid posting secrets, tokens, private keys, exploit payloads, or private conversation content.
Security-sensitive areas include:
- The installer writing to
~/.codex/skillsor~/.claude/skills. - Any future host integration that handles structured choices.
- Any future logic that writes project context docs.
The package no longer creates local recovery journals or hidden cache directories. It does not require gstack telemetry, analytics, or runtime commands. Project context docs should not store credentials, tokens, private keys, or sensitive personal data.
For confirmed vulnerabilities, the expected response is:
- Reproduce the issue.
- Patch the smallest affected surface.
- Add a regression test when practical.
- Publish a patch release.
- Credit the reporter unless they ask to stay anonymous.