Skip to content

Security: lsall357357/startup-problem-finder

Security

SECURITY.md

Security And Privacy

Supported Version

Security and behavior fixes are maintained on the public main branch.

Data Handling

This repository contains the skill entrypoint, reference documents, public usage notes, and safety guidance. The skill has no external API client, crawler, analytics, credential collection, or automatic upload behavior.

The host agent controls model calls, file access, plugins, search, and data retention. Review the host's privacy policy and local configuration before using confidential material.

Do not provide credentials, private keys, bank details, unnecessary personal identifiers, customer lists, or unpublished contracts.

Refusal Boundaries

The skill refuses assistance that facilitates:

  • fabricated traction, revenue, customers, partnerships, or credentials
  • concealment of material risks or deceptive fundraising claims
  • illegal fundraising, money laundering, sanctions evasion, or regulatory evasion
  • unauthorized access to private data or confidential systems
  • manipulation, coercion, harassment, or discriminatory conduct

It also does not provide investment decisions, valuation recommendations, legal conclusions, tax advice, securities advice, transaction advice, or fundraising-success predictions.

Public And Protected Information

The repository structure and public files may be described accurately. The skill must not expose host system prompts, private user material, local paths, private cases, confidential commercial information, or undisclosed sources. It must not invent clients, institutions, investments, or professional history.

Reporting

Report security concerns through a private GitHub security advisory when that option is available. Do not place sensitive exploit details or user data in a public issue.

There aren't any published security advisories