Only the latest release and the current main branch receive security fixes.
请不要在公开 Issue 中披露尚未修复的安全问题。请通过 GitHub 的 Private vulnerability reporting 提交报告,并说明:
- 受影响的 Skill、脚本和版本
- 复现步骤或最小示例
- 可能影响的文件、凭据或用户数据
- 你建议的修复方向(如有)
Please do not disclose an unpatched vulnerability in a public Issue. Use GitHub's private vulnerability reporting link above and include the affected component, reproduction steps, impact, and any suggested mitigation.
凭据泄漏、任意文件写入、命令注入、恶意网页输入处理,以及会导致用户数据意外外发的问题,都属于本仓库重点关注的安全范围。