Skip to content

Security: RobLe3/ynm-skill

SECURITY.md

Security Policy

YNM is primarily a methodology, but its optional scripts can inspect and, when explicitly authorized, create project files. Report path traversal, unintended mutation, ownership-boundary failures, secret exposure, or unsafe release-validation behavior through GitHub's Security tab by selecting Report a vulnerability, when that option is available.

If private vulnerability reporting is unavailable, open a public issue containing only a sanitized description and ask the maintainer to establish a private channel. Never include credentials, proprietary project content, exploit-sensitive details, or personal data in a public issue. State the YNM version, affected script or contract, invocation, expected boundary, observed behavior, and a minimal sanitized reproduction.

There aren't any published security advisories