Security and behavior fixes are maintained on the public main branch.
This repository contains the skill entrypoint, reference documents, public usage notes, and safety guidance. The skill has no external API client, crawler, analytics, credential collection, or automatic upload behavior.
The host agent controls model calls, file access, plugins, search, and data retention. Review the host's privacy policy and local configuration before using confidential material.
Do not provide credentials, private keys, bank details, unnecessary personal identifiers, customer lists, or unpublished contracts.
The skill refuses assistance that facilitates:
- fabricated traction, revenue, customers, partnerships, or credentials
- concealment of material risks or deceptive fundraising claims
- illegal fundraising, money laundering, sanctions evasion, or regulatory evasion
- unauthorized access to private data or confidential systems
- manipulation, coercion, harassment, or discriminatory conduct
It also does not provide investment decisions, valuation recommendations, legal conclusions, tax advice, securities advice, transaction advice, or fundraising-success predictions.
The repository structure and public files may be described accurately. The skill must not expose host system prompts, private user material, local paths, private cases, confidential commercial information, or undisclosed sources. It must not invent clients, institutions, investments, or professional history.
Report security concerns through a private GitHub security advisory when that option is available. Do not place sensitive exploit details or user data in a public issue.