Skip to content
This repository was archived by the owner on May 20, 2026. It is now read-only.

Security: jacob-balslev/skill-audit-loop

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Report security issues privately via GitHub Security Advisories:

πŸ‘‰ https://github.com/jacob-balslev/skill-audit-loop/security/advisories/new

Please do not open a public issue for security reports.

If you cannot use GitHub Security Advisories, email jacobbalslev@gmail.com with the subject line [security] skill-audit-loop β€” <short description>.

Response SLA

Phase Target
Triage acknowledgement within 7 calendar days of report
Initial assessment within 14 days
Fix or mitigation plan within 30 days for high-severity issues; 90 days otherwise

These are targets, not guarantees. Single-maintainer project β€” please be patient and follow up if you have not heard back.

Scope

In scope:

  • Source code in src/ and published @skill-graph/audit npm package.
  • Eval fixtures and grader scripts in evals/ and src/graders/.
  • Documentation in this repository.

Out of scope:

  • Skills audited by this tool (they are owned by their respective libraries).
  • Forks of this repo published outside github.com/jacob-balslev.
  • Vulnerabilities in upstream dependencies β€” please report to those projects.
  • Issues in the sibling repos (skill-metadata-protocol, skill-graph, skills) β€” file those against the respective repo.

Coordinated Disclosure

We follow coordinated disclosure. Reporters will be credited in the published security advisory once a fix is released, unless the reporter requests anonymity.

Supported Versions

Only the latest minor release line on main receives security fixes. Older lines are upgrade-only.

There aren't any published security advisories