Skip to content

Security: sandbaseai/workbuddy-skill

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use a private GitHub security advisory with reproduction steps, affected paths or versions, and any relevant logs with secrets removed.

If private advisories are unavailable, open a minimal issue asking for a private reporting channel without including exploit details.

Automated protections

This public repository has GitHub Dependabot security updates, Secret Scanning, and Push Protection enabled. A push that contains a detected credential may be blocked; revoke and rotate exposed credentials instead of disabling the protection.

Catalog safety boundary

The catalog contains links and metadata for public SKILL.md files. A catalog entry is not an endorsement, compatibility approval, or security scan. Do not execute or install a third-party Skill solely because it appears in the index. Review its license, instructions, scripts, network behavior, and requested permissions in the original repository first.

Please never submit credentials, private prompts, customer data, or proprietary Skill bodies in issues or pull requests.

There aren't any published security advisories