Skip to content

Security: balgaly/command-giffer

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in command-giffer, please do not open a public issue.

Instead:

  1. Email balgaly@gmail.com with a description of the vulnerability
  2. Include steps to reproduce if possible
  3. Allow reasonable time for a fix before any public disclosure

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix: Depends on severity — critical issues are prioritized

Scope

This policy covers the command-giffer skill and its HTML/GIF generation code.

Security Practices

  • No network access required
  • No telemetry or data collection
  • Operates entirely on local files

Thank You

Security reports are taken seriously. Contributors who responsibly disclose vulnerabilities will be credited (unless they prefer to remain anonymous).

There aren't any published security advisories