Security
Supported Versions
| Version | Supported |
|---|---|
| 2.x | ✅ |
| < 2.0 | ❌ |
Reporting a Vulnerability
If you discover a security issue in pm-skills, report it privately first.
Preferred channel:
- Use GitHub Private Vulnerability Reporting:
Fallback channel:
- Open a GitHub issue requesting a private follow-up (do not include exploit details or secrets):
What to include:
- Affected file(s) or workflow(s)
- Reproduction steps
- Impact assessment
- Suggested remediation (if available)
Response targets:
- Initial acknowledgement within 2 business days
- Ongoing status updates until resolution
Scope
This policy covers:
- Repository content (
skills/,commands/,_workflows/, docs, templates) - Build/release tooling and GitHub Actions workflows
- Published release artifacts
Out of Scope
The following are generally out of scope for this repository:
- Vulnerabilities in third-party tools or clients not maintained here
- Security behavior of external AI platforms integrating these skills