If you discover a security issue in agents-audit or the CLI packages in this
repository, please report it through the GitHub security workflow for this
repository.
- a short summary of the issue
- affected package or command path
- reproduction steps
- whether the issue affects published packages or only local development
- public issue reports for sensitive vulnerabilities before coordinated disclosure
- secrets, tokens, or private repository data
This repository publishes agents-audit. @workspacejson/cli is private and
is not distributed. Issues in @workspacejson/spec or @workspacejson/rules
belong to workspacejson/standard.