| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| < 1.2.0 | ❌ |
If you discover a security vulnerability, please report it responsibly.
DO NOT open a public GitHub issue for security vulnerabilities.
- Email: Send details to iamnaime@builderhall.com
- Subject:
[SECURITY] engineering-docs - [brief description] - Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment within 48 hours
- Status update within 7 days
- Fix timeline depends on severity
This plugin:
- ✅ Does not collect or transmit user data
- ✅ Does not require network access
- ✅ Does not execute arbitrary code (skills are markdown instructions)
- ✅ Does not store credentials or tokens
- ✅ All scripts are open source and auditable
When using this plugin with AI agents:
- Skills are markdown instructions — they don't execute code directly
- Scripts in
scripts/andscripts/are utility tools that run locally - The MCP server (
scripts/validate.js) only reads files, doesn't modify them - Hooks (
hooks/check-progress.js) only read status, don't modify anything
- Review skills before use — Read SKILL.md files to understand what instructions the agent will follow
- Don't share sensitive data — Skills don't need your credentials or API keys
- Use version control — Track all documentation changes in git
- Validate outputs — Review generated documents before using them
We appreciate responsible disclosure and will credit reporters (unless they prefer anonymity).
- Security: iamnaime@builderhall.com
- General: GitHub Issues