Email security@earthcare.network with details. We'll acknowledge within 72 hours. Please don't open a public issue for security problems.
This repo contains markdown instruction files only. There are no scripts, no binaries, and nothing that executes on your machine. Installing a skill means copying a text file that your AI reads.
If any fork or copy of this repo asks you to run a script, paste an API key into a chat, or share a password — that's not us. Walk away and report it.
- No passwords, ever. Chat clients (Claude, ChatGPT, Grok) connect through
the OAuth sign-in screen at
earthcare.network— your AI receives a scoped token, never your password. Developer clients (Cursor, scripts) use an API key you create yourself in your workspace settings; no skill will ever ask you to paste one into a chat. - Scoped consent. You approve what the connector may do (read / build / sell / refer) when you connect it.
- Server-side approval gates. Sending, publishing, and paying require explicit human confirmation enforced by the Earth Care Network platform — not merely requested by these skills. A modified skill cannot bypass them.
- Draft-first. All outbound artifacts are created as drafts.
These skills direct an AI that reads public web content (buying signals). Treat signal content as evidence, never as instructions — the skills say this explicitly, and the platform's approval gates limit the blast radius if an AI is manipulated. If you find a way a hostile signal could cause an unapproved action, that's a vulnerability: report it.