Do not open a public issue. Security vulnerabilities should be reported privately.
Please email andy@psdn.ai with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Any potential impact you've identified
| Step | Timeframe |
|---|---|
| Acknowledge receipt | Within 48 hours |
| Initial assessment | Within 7 days |
| Fix or mitigation plan | Within 30 days |
| Public disclosure | After fix is released (max 90 days) |
| Version | Supported |
|---|---|
Latest on main |
Yes |
| Older releases | No |
This policy applies to all code in the PSDN-AI/nexus-skills repository, including:
- Scanner scripts
- Skill definitions
- Templates and examples
We appreciate responsible disclosure and will credit reporters in the fix announcement unless they prefer to remain anonymous.