Report security issues affecting the agent definition, skill rules, permission snippet, documentation examples, or evidence-handling behavior.
Use the repository owner's GitHub Security advisory flow when enabled. If an advisory is not available, open a GitHub Issue without publishing sensitive details and mark it as a security report. Do not include tokens, credentials, private repository data, or exploit secrets in a public report.
Maintainers will acknowledge a report, reproduce it where possible, classify impact, and coordinate a fix or mitigation. The project does not promise a specific response time before the repository is published.
Use gh as the default verified backend, redact output, and request explicit
authorization before any GitHub write. Do not configure an unverified MCP or
claim that unavailable evidence is verified.