Report vulnerabilities in these skills, release artifacts, or repository
automation to security@meteor.com.
Include the affected skill, file, or release; the impact; reproduction steps; and a suggested mitigation when available. Do not open a public issue for an undisclosed vulnerability.
Reports are acknowledged within two working days and receive a more detailed response within six working days.
Report vulnerabilities in third-party clients, runtimes, or dependencies to their maintainers unless this repository's guidance or automation causes the issue.