Please do not open a public issue for security vulnerabilities.
To report a vulnerability privately:
- Open a private security advisory (if available), or
- Email the maintainer (see repository profile for contact).
- Affected version / commit
- Steps to reproduce
- Impact description
- Suggested fix (optional)
- Acknowledgment within 3 business days
- Initial assessment within 7 business days
- Fix and release within 30 days (depending on severity)
This project only ships workflow code, prompt templates, and schemas. It does not contain copyrighted content or secrets. Vulnerabilities of interest include prompt injection in parser prompts, sandbox escape attempts, and unsafe file handling.