Do not report security-sensitive information in a public GitHub issue.
Security-sensitive Agent Skill issues include unsafe infrastructure guidance, credential mishandling, weakened access controls, sensitive configuration exposure, unsafe MCP server behavior, or dangerous product usage patterns. HashiCorp employees should use the established internal security reporting process and privately notify the owning maintainers. If no approved private reporting route is available, ask a known maintainer for the current route without disclosing sensitive details publicly.
For non-sensitive correctness issues, use the Skill bug template. Remove all credentials, account identifiers, infrastructure addresses, logs containing secrets, and private configuration before sharing a reproducer.