What this covers
Report issues in the harness-first plugin or this catalog: suspected vulnerabilities, credential exposure, unsafe scripts, or harmful package behavior. The package is Markdown skills and static assets. It has no backend, MCP server, connectors, authentication, telemetry, analytics, hidden network calls, or runtime downloads.
How to report
Follow the repository security policy and use GitHub private vulnerability reporting when you can. Email security@stark-ai.de if you cannot use GitHub.
Include the affected version or commit, whether a plugin copy or archive is involved, the skill or path, the impact, steps to reproduce, and a sanitized proof. If a public URL, marketplace entry, or portal artifact is involved, say whether it is local, draft, external, or verified. Do not imply a stronger status.
What not to include
Do not send secrets, live credentials, customer data, private repository paths, or exploit payloads that are unnecessary to understand the issue. Do not open a public issue for a suspected vulnerability.
Ordinary bugs
Install, documentation, and source questions that are not security issues belong on Support or GitHub.