Skip to content

Security: gfernandf/agent-skill-registry

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x Yes
0.1.x Yes

Reporting a Vulnerability

If you discover a security vulnerability, please report it privately:

  1. Email: gfernandf+security@gmail.com
  2. Subject: [SECURITY] agent-skill-registry — <brief description>
  3. Include: affected version, reproduction steps, and potential impact.

Do NOT open a public GitHub issue for security vulnerabilities.

We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 business days for critical issues.

Scope

This policy covers:

  • The agent-skill-registry (this repository)
  • Capability and skill YAML definitions
  • Governance tooling shipped in this repository

Third-party tools and external integrations are outside scope.

There aren’t any published security advisories