Skip to content

Security: weizesunmd-byte/diving-in-research

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest version on the default branch. Until the first stable release, earlier alpha versions are not maintained.

Reporting a vulnerability

Use GitHub private vulnerability reporting when it is enabled for the repository. If it is unavailable, open a minimal issue asking the maintainers for a private reporting channel. Do not include exploit details, credentials, cookies, tokens, browser storage, personal data, or private URLs in a public issue.

Please include the affected Skill and version, the security boundary involved, the smallest safe reproduction, and the likely impact. Maintainers should acknowledge a report within seven days; this is a target, not a service-level guarantee.

Security boundaries

These Skills are instruction packages and small local scoring utilities. They do not provide a proxy network, CAPTCHA bypass, anti-detection system, account automation, credential vault, or guarantee against platform restrictions.

Users must authenticate only through an official platform page, the browser used by their Agent, an official connector, or a documented local CLI flow. Never paste passwords, verification codes, cookies, access tokens, SSH keys, or Zhihu Access Secrets into an Agent conversation.

Research is read-only and bounded. A CAPTCHA, rate limit, account warning, or unexpected authentication prompt is a stop condition, not an obstacle to work around. The Skills fall back to public sources and lower confidence when an authenticated capability is unavailable.

There aren't any published security advisories