Please report security problems privately, through the repository's Security → Report a vulnerability page, not in a public issue. Say what an attacker can do, what they need first, and how to reproduce it. The maintainers aim to reply within a week.
If it is a vulnerability, you get a fix or a mitigation, and a line in the changelog crediting you by whatever name you choose, or none. If it is not, you get the reasoning, and you are free to write about it publicly.
Only the latest release is supported.
Useful context for judging whether something is a vulnerability:
- The hooks run on every prompt and tool call of the Claude Code sessions
they are wired into, as your user. They read the hook's payload and the
session transcript, and write only under
~/.claude/skill-plus-plus/. - The review page (
skill-plus-plus web) listens on127.0.0.1only and has no login, because only processes on your machine can reach it. It refuses a request whoseHostis not that address, and a POST that is not JSON or comes from another page'sOrigin, because a POST can start your agent or write a skill into a repository. Install writes one folder, the skill's, into the project the candidate belongs to, and never over a folder already there; that path is built from the ledger, never from the request. - The Skills tab changes skills already in a project, named by project and
folder, never by a path from the request. Opening one reads its
SKILL.mdonly, and never through a link. Edit runs the same agent as drafting, on a copy of the skill in a temporary folder, and writes the result into the skill only on Apply, after checking that the skill did not change meanwhile. A change to the project's copy while the agent runs is detected, and then nothing is proposed. Undo writes back the copy the edit was made on: only for the last Apply, with the token that Apply gave the page, and only while the skill holds exactly what it wrote. - The drafting agent (
skill-plus-plus draft, Draft Skill) is whateverSKILL_PLUS_PLUS_AGENTnames, by defaultclaude -pallowedRead,Write,Editandpython3 bin/skill-plus-plus. It runs in a temporary folder and reads one candidate. What it can reach beyond that is decided by the agent and its permissions, not by Skill++. - Scrubbing removes credential-shaped strings and email addresses from prompts, tool calls and replies; the working directory is kept as it is. It is a net, not a guarantee; what it does not catch is listed in docs/privacy.md. A secret that gets past it and into the ledger is worth reporting.
- Anything that needs someone to already run code as your user on your machine.
- What your own agent or its model provider does with a prompt you sent.
- Skills you install or upload yourself; read a generated skill before installing it.