Skip to content

Security: sandeep-mewara/lifecycle-agent-orchestrator

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly. Do not open a public GitHub issue for security vulnerabilities.

Instead, please email the maintainer directly or use GitHub's private vulnerability reporting.

Scope

This project is a set of AI coding plugin skills (markdown files and shell scripts). It does not run a server, store user data, or process credentials. Security concerns are most likely to involve:

  • Skill instructions that could lead to unsafe code generation patterns
  • Validation scripts with shell injection vulnerabilities
  • Accidental inclusion of sensitive data in examples or documentation

Response

The maintainer will acknowledge receipt within 48 hours and provide an estimated timeline for a fix. Security patches will be released as soon as practical.

There aren't any published security advisories