Skip to content

Security: nanlong/rust-engineer-skill

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest release and the default branch.

Reporting a Vulnerability

Do not open a public issue for a vulnerability that could expose credentials, execute untrusted commands, weaken sandbox boundaries, or enable prompt injection through evaluation data. Use the repository host's private security-advisory feature after publication.

Include the affected revision, threat model, reproduction steps, impact, and a minimal remediation idea when available. Maintainers should acknowledge a report promptly, coordinate disclosure, and credit the reporter unless anonymity is requested.

Trust Boundary

This repository contains instructions and local validation tools. Review changes before installation, pin revisions in high-assurance environments, and do not treat model-generated grades as a security audit. The behavior grader treats candidate output as untrusted data, but model isolation is not a substitute for process sandboxing.

There aren't any published security advisories