Security fixes are applied to the latest published release of @sx4im/skillcheck
on npm. Older versions are not backported unless a critical issue warrants it.
Please do not open a public GitHub issue for security vulnerabilities.
Report privately via one of:
- GitHub Security Advisories — use Report a vulnerability on this repository (preferred).
- Email the maintainer — contact listed on https://github.com/sx4im if advisory filing is unavailable.
Include enough detail to reproduce the issue (affected version, environment, and steps). You should receive an acknowledgement within a few days; we will coordinate disclosure after a fix is available when possible.
- API keys and tokens stored by the CLI under
~/.config/skillcheck/are local credentials — treat them like secrets and never commit them. - The hosted dashboard proxies model calls; do not send production secrets into public issue trackers or sample skills.