Skip to content

Security: coreplanelabs/skills

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report vulnerabilities privately through GitHub's private vulnerability reporting on this repository:

https://github.com/coreplanelabs/skills/security/advisories/new

Do not open a public issue for a security problem.

Scope

This repository contains no executable code — only agent skills, rules, and commands (Markdown), plus the plugin manifests and MCP endpoint declarations that point coding agents at Polylane's hosted MCP servers. Issues in the Polylane service itself (the MCP servers, the API, or anything behind mcp.polylane.com / docs.polylane.com) belong to Polylane; report those through the same private advisory link and we will route them.

There aren't any published security advisories