Agent Skill Doctor is currently an alpha project. Security fixes are applied on a best-effort basis to the latest release and the default branch; older versions may not receive patches.
Agent Skill Doctor 当前处于 Alpha 阶段。安全修复会尽力应用到最新版本和默认分支,旧版本不保证获得补丁。
Please do not open a public issue for a suspected vulnerability.
请不要通过公开 Issue 报告疑似漏洞。
This project does not publish a private security email. Use GitHub's private vulnerability reporting instead:
本项目暂未公布安全报告邮箱,请使用 GitHub 私密漏洞报告功能:
- Open this repository's Security tab. / 打开本仓库的 Security 页面。
- Select Advisories, then Report a vulnerability. / 进入 Advisories,选择 Report a vulnerability。
- Include the affected version or commit, impact, reproduction steps, and a minimal proof of concept. / 提供受影响版本或提交、影响、复现步骤和最小化 PoC。
- Remove credentials, personal data, and unrelated third-party content before submitting. / 提交前移除凭据、个人信息和无关第三方内容。
If private vulnerability reporting is unavailable, do not post technical details publicly. Open a detail-free issue asking maintainers to enable a private reporting channel.
如果私密报告入口不可用,请勿公开技术细节;可创建一个不含漏洞详情的 Issue,请维护者启用私密报告渠道。
Examples include arbitrary code execution, path traversal or unintended file access, secret disclosure, unsafe GitHub Action behavior, and bypasses of documented security boundaries.
例如:任意代码执行、路径穿越或非预期文件访问、敏感信息泄露、GitHub Action 的不安全行为,以及绕过已声明安全边界的问题。
A suspicious instruction found in a third-party Skill is normally a finding for that Skill, not a vulnerability in Agent Skill Doctor. It becomes relevant here when the scanner handles it unsafely or fails a documented guarantee.
第三方 Skill 中的可疑指令通常属于该 Skill 的问题,而非 Agent Skill Doctor 漏洞;只有当扫描器处理不安全,或违反已声明保证时,才属于本项目安全问题。
Maintainers will review reports privately, confirm scope, coordinate a fix when possible, and credit reporters who want attribution. As a volunteer alpha project, no fixed response-time SLA is promised. Please allow time for a patch before public disclosure.
维护者会私下评估报告、确认范围、尽可能协调修复,并按报告者意愿致谢。由于项目仍是志愿维护的 Alpha 版本,目前不承诺固定响应 SLA;请在公开披露前预留修复时间。