Skip to content

Security: fkfkg/Agent-Library

Security

SECURITY.md

Security Policy

Responsible use of offensive-security content

Claude Arsenal includes skills and agents for penetration testing, red-teaming, malware analysis, and related topics. These are provided for defensive and authorized use only:

  • Your own systems and infrastructure
  • Engagements with explicit written authorization and defined scope
  • Capture-the-Flag (CTF) competitions
  • Isolated, disposable lab environments

Do not use this content to access, disrupt, or test systems you do not own or lack permission to test. Malware samples must only be handled in isolated environments and never executed on production or shared networks.

Reporting a vulnerability

If you find a security issue in this repository (e.g., a skill that leaks secrets, unsafe example code, or a supply-chain concern), please open a GitHub issue marked security, or contact the maintainers privately if the issue is sensitive. Please include:

  • A clear description and impact
  • Steps to reproduce
  • Any suggested remediation

We aim to acknowledge reports promptly and address confirmed issues quickly.

Scope note

The skill/agent content is instructional Markdown. It executes nothing by itself; risk comes from how generated code or commands are used. Always review AI-generated code before running it.

There aren't any published security advisories