Email security@graycodeai.com with a description, affected files or skills, and reproduction steps. Please do not open a public issue for a vulnerability. GitHub private vulnerability reporting is not enabled for this repository yet; when it is, the "Report a vulnerability" button on the Security tab will work too.
We aim to acknowledge reports within 48 hours, assess scope, prepare a fix, and publish an advisory when the fix ships.
GrayCode Skills is pre-1.0. Only the current main branch and the registry
currently published on the registry-latest release are supported; fixes are
not backported.
SKILL.mdinstruction packages and optional helper scripts undercategories/. Most are ingested community content, and scripts run with the permissions of whoever executes them. Review a skill before you install it.registry.json, generated by CI and published with an Ed25519registry-signature.json. The public key is committed atkeys/registry-ed25519.pub; see docs/REGISTRY.md for how to verify.- Python tooling under
tools/(validation, registry, packaging).
tools/check_secrets.py --strict: credential patterns in skill content.tools/check_shell_commands.py --strict: unallowlisted download-and-execute (curl | sh) patterns.tools/check_changed_scripts.pyplus a sandboxed--helpsmoke run of changed skill scripts (network-less container).tools/check_licenses.py: copyleft license gate (see NOTICE).pip-audit: known vulnerabilities in the Python dependencies.ruff check: static analysis of the tooling.- OpenSSF Scorecard, with every GitHub Action pinned to a commit SHA.
This repository contains no Go code and no container vulnerability scanner runs in CI.
- Give us reasonable time to fix the issue before public disclosure.
- Do not exploit the vulnerability beyond what is needed to demonstrate it.
- Do not publish details that enable widespread exploitation before a fix is available.