Please report vulnerabilities privately through GitHub's security-advisory feature after the repository is published. Do not include credentials or private skill bodies in a public issue.
Skill-Leaf treats catalogues and skill libraries as untrusted local input. A security report is especially useful when it demonstrates path escape, symlink traversal, hash-verification bypass, unbounded resource use, or unintended execution.
Federated snapshots transfer only indexed Markdown. Unpinned snapshots are downgraded to untrusted, protocol versions must overlap, and chunk, file, manifest and catalogue hashes fail closed before a domain is rebound. Storage-provider access control is not retroactive revocation of already downloaded content.