Private vulnerability reporting

Security

Use a private channel for suspected vulnerabilities, credential exposure, or harmful package behavior. Do not disclose sensitive details in a public issue.

What this covers

Report issues in the harness-first plugin or this catalog: suspected vulnerabilities, credential exposure, unsafe scripts, or harmful package behavior. The package is Markdown skills and static assets. It has no backend, MCP server, connectors, authentication, telemetry, analytics, hidden network calls, or runtime downloads.

How to report

Follow the repository security policy and use GitHub private vulnerability reporting when you can. Email security@stark-ai.de if you cannot use GitHub.

Include the affected version or commit, whether a plugin copy or archive is involved, the skill or path, the impact, steps to reproduce, and a sanitized proof. If a public URL, marketplace entry, or portal artifact is involved, say whether it is local, draft, external, or verified. Do not imply a stronger status.

What not to include

Do not send secrets, live credentials, customer data, private repository paths, or exploit payloads that are unnecessary to understand the issue. Do not open a public issue for a suspected vulnerability.

Ordinary bugs

Install, documentation, and source questions that are not security issues belong on Support or GitHub.