Responsible Security Disclosure

Prepare and route confidential vulnerability reports under the receiving project's policies, with authorization checks, evidence verification, sensitive-data redaction, coordinated disclosure, and human approval. Use when a suspected vulnerability may need to be reported to an upstream project, vendor, maintainer, or security team. Do not use for routine code review, public bug reports, incident response, or unauthorized security testing.

mgifford 747a730 5 files · 13.9 KB Updated

File contents

mgifford/upstream-first/tree/main/skills/responsible-security-disclosure commit 747a730f94

Frequently asked questions

npx skillmds@latest add mgifford/responsible-security-disclosure