Skip to content

Security: balgaly/skit

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in skit, please do not open a public issue.

Instead:

  1. Email balgaly@gmail.com with a description of the vulnerability
  2. Include steps to reproduce if possible
  3. Allow reasonable time for a fix before any public disclosure

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix: Depends on severity — critical issues are prioritized

Scope

This policy covers the skit CLI tool and its npm package. It does not cover third-party skills installed via skit.

Security Practices

  • Skills are installed from Git repositories — users should verify skill sources before installing
  • No telemetry or data collection
  • No credentials stored by the tool

Thank You

Security reports are taken seriously. Contributors who responsibly disclose vulnerabilities will be credited (unless they prefer to remain anonymous).

There aren't any published security advisories