Skip to content

Security: greg-asher/oh-my-lawd

Security

SECURITY.md

Security Policy

Scope

This repository is a public specification project.

Primary risks for this repository are:

  • accidental publication of sensitive information
  • malicious or misleading changes to normative documents
  • prompt-pack changes that weaken safeguards or collapse layer boundaries

Reporting

Do not open a public issue for sensitive reports.

If you discover a security issue, leaked credential, or abuse concern related to this repository, contact the maintainer privately through GitHub security reporting or direct maintainer contact if available.

Include:

  • affected file or path
  • description of the issue
  • why it matters
  • whether the issue is public already
  • any recommended immediate containment steps

What To Report

Examples:

  • exposed secrets or tokens
  • malicious links or payloads in docs or prompts
  • prompt-pack instructions that encourage unsafe behavior
  • governance gaps that would allow unreviewed mutation of normative files
  • misleading claims of affiliation, endorsement, or official status

Out Of Scope

The following are generally not security issues for this repository:

  • editorial disagreements
  • non-sensitive formatting issues
  • ordinary spec ambiguity without security impact

Use regular issues for those cases.

There aren't any published security advisories