Security policy

July 26, 2026 ยท View on GitHub

Supported versions

Security fixes are applied to the latest published release.

Reporting

Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for f0d010c/skillforge, including a minimal reproduction, affected version, impact, and suggested mitigation when available.

SkillForge reads untrusted repository content. Reports involving path traversal, symlink escape, unintended file inclusion, archive corruption, command execution, or denial of service are especially useful.