Security fixes are applied to the latest version on the default branch. Until the first stable release, earlier alpha versions are not maintained.
Use GitHub private vulnerability reporting when it is enabled for the repository. If it is unavailable, open a minimal issue asking the maintainers for a private reporting channel. Do not include exploit details, credentials, cookies, tokens, browser storage, personal data, or private URLs in a public issue.
Please include the affected Skill and version, the security boundary involved, the smallest safe reproduction, and the likely impact. Maintainers should acknowledge a report within seven days; this is a target, not a service-level guarantee.
These Skills are instruction packages and small local scoring utilities. They do not provide a proxy network, CAPTCHA bypass, anti-detection system, account automation, credential vault, or guarantee against platform restrictions.
Users must authenticate only through an official platform page, the browser used by their Agent, an official connector, or a documented local CLI flow. Never paste passwords, verification codes, cookies, access tokens, SSH keys, or Zhihu Access Secrets into an Agent conversation.
Research is read-only and bounded. A CAPTCHA, rate limit, account warning, or unexpected authentication prompt is a stop condition, not an obstacle to work around. The Skills fall back to public sources and lower confidence when an authenticated capability is unavailable.