Skip to content

Security: eddiepohj/planrunner-skills

Security

SECURITY.md

Security policy

Supported releases

Security fixes are applied to the latest tagged release.

Reporting a vulnerability

Use the repository host's private security-advisory feature, or email eddie.pohjavirta@gmail.com. Do not include credentials, private plans, run ledgers, transcripts, or proprietary source in a public issue.

Trust model

Runner plans are executable input. A plan can ask workers to modify files and can contain shell verification commands. Review a plan before running it and use the runners only in a project you trust. Generated ledgers, logs, gate artifacts, and reviewer prompts can contain source code, paths, and plan text; scan them before publication.

Max Runner sends gate artifacts to the configured Codex reviewer over the network. Plan Runner and Light Runner do not make package-owned network requests, although a user plan, worker, verification command, or host agent may do so.

There aren't any published security advisories