Security fixes are applied to the latest release on the default branch.
Report suspected vulnerabilities privately through GitHub private vulnerability reporting when available. Do not open a public issue containing exploit details, credentials, private infrastructure, or customer data.
Relevant issues include unsafe generated commands, credential leakage patterns, insecure installation guidance, untrusted companion repositories, validator bypasses, archive traversal, malicious executable inclusion, or workflows that imply unauthorized production changes.
This Skill generates architecture guidance and local artifacts. It does not authorize deployment, provisioning, migration, deletion, credential rotation, access changes, purchases, or external installation without explicit approval.