Report vulnerabilities to security@tokenpolice.ai. Do not open a public issue for security reports.
We acknowledge reports within 3 business days and aim to ship a fix within 90 days of confirmation. Please include the skill name, the release tag or commit, a description of the issue, and steps to reproduce.
These skills are instructions and reference notes that a coding agent reads; they contain no executable code. The token-police-sdk skill does ask the agent to send TokenPolice a metadata-only integration report, authenticated with your API key: the app name, the providers and frameworks it found with their versions, how far the integration got, and the agent's own notes — never source code, file paths, environment values or prompts. The agent tells you this before the first report. The SDK it helps you install sends only token counts and the session metadata you attach — never prompt or completion text. See https://tokenpolice.ai/privacy.