Security policy
July 26, 2026 ยท View on GitHub
Supported versions
Security fixes are applied to the latest published release.
Reporting
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for f0d010c/skillforge, including a minimal reproduction, affected version, impact, and suggested mitigation when available.
SkillForge reads untrusted repository content. Reports involving path traversal, symlink escape, unintended file inclusion, archive corruption, command execution, or denial of service are especially useful.