If you find a security issue in a curated skill, validation script, or registry automation, report it privately to the maintainers before opening a public issue.
Security reports are especially relevant for:
- helper scripts shipped inside skills
- validation and catalog-generation automation
- provenance or trust-state mistakes that could misrepresent a skill
Please include reproduction steps, affected paths, and impact assessment.