Do not open a public issue for a suspected credential leak or exploitable skill. Use GitHub's private vulnerability reporting for this repository.
Skills are untrusted code and instructions until reviewed. CI scanning reduces risk but does not prove that runtime behavior is safe. Consumers must still run skills with least privilege and review requested filesystem, network, and tool access.