This repository publishes public methodology drafts, reference patterns, schemas, and examples for Schema Sandbox.
Security reports are welcome for:
- Dangerous or misleading permission-scope examples
- Unsafe manifest examples
- JSON Schema mistakes that could encourage unsafe implementations
- Documentation that may cause incorrect assumptions about production safety
This repository does not provide a production runtime, hosted service, certification service, or official industrial adapter. Vulnerabilities in independent implementations should be reported to their maintainers.
Open a GitHub issue for documentation or example-safety concerns. If a report involves sensitive information, contact the maintainers privately through the contact channel listed on SchemaSandbox.com.
The public methodology is not a production security guarantee. Production use requires independent threat modeling, implementation review, testing, compliance review, and incident-response planning.