← Về thư mục
📄 / / root / ceo-project / academic-research-skills / SECURITY.md

Security Policy

Supported versions

Only the latest release on the main branch receives security fixes.

Version Supported
Latest (main) Yes
Older releases No

Reporting a vulnerability

If you find a security issue (e.g. prompt injection, credential exposure, unintended data exfiltration through API calls), do not open a public issue.

Instead, use GitHub's private vulnerability reporting:

  1. Go to the Security Advisories page.
  2. Click "Report a vulnerability".
  3. Fill in the details — what you found, how to reproduce it, and the potential impact.

You will receive a response within 7 days. If the report is accepted, a fix will be issued and credited in the release notes. If declined, you will receive an explanation.

Scope

The following are in scope for security reports:

The following are out of scope: