This repository is a public specification project.
Primary risks for this repository are:
- accidental publication of sensitive information
- malicious or misleading changes to normative documents
- prompt-pack changes that weaken safeguards or collapse layer boundaries
Do not open a public issue for sensitive reports.
If you discover a security issue, leaked credential, or abuse concern related to this repository, contact the maintainer privately through GitHub security reporting or direct maintainer contact if available.
Include:
- affected file or path
- description of the issue
- why it matters
- whether the issue is public already
- any recommended immediate containment steps
Examples:
- exposed secrets or tokens
- malicious links or payloads in docs or prompts
- prompt-pack instructions that encourage unsafe behavior
- governance gaps that would allow unreviewed mutation of normative files
- misleading claims of affiliation, endorsement, or official status
The following are generally not security issues for this repository:
- editorial disagreements
- non-sensitive formatting issues
- ordinary spec ambiguity without security impact
Use regular issues for those cases.