Please do not open public issues for vulnerabilities.
Report security concerns privately to the maintainers. If no dedicated security contact is listed for a fork or downstream project, contact the repository owner through a private channel and include enough detail to reproduce or assess the issue.
Helpful report details:
- Affected file, template, command, skill, or document.
- Steps to reproduce.
- Potential impact.
- Suggested fix, if known.
Security reports for this repository may cover:
- Templates in
.specs/and.tasks/. - Skills in
.codex/skills/. - Commands in
.codex/commands/. - Repository documentation.
- Guidance that could lead users to unsafe handling of secrets, credentials, dependencies, generated code, or deployment settings.
FactoryOS does not currently ship application code, a hosted service, or runtime infrastructure in the base scaffold.
- Give maintainers reasonable time to assess and fix reported issues.
- Do not disclose vulnerabilities publicly before maintainers have responded.
- Do not access, modify, or exfiltrate data that is not yours.
- Do not use testing methods that degrade services or systems.