← Files Mermaid DiagramsARCHIVED FILE
SECURITY.md
1.35 KB · Oct 2, 2026 · 00:31 UTC
# Security policy ## Supported versions Version 2.1.x is the current feature and security line. Version 2.0.1 receives critical security fixes during the 2.1 migration window, and version 1.x remains available for its frozen contract. Withdrawn releases are unsupported. ## Reporting Report non-sensitive defects through the [public issue tracker](https://github.com/theisegoria/chatgpt-skill-plugins/issues). For a vulnerability that would put users at risk if disclosed publicly, contact the repository owner through the private reporting channel available on the GitHub repository. Do not include secrets or private generated files in a public report. Support and security response are best-effort; no response-time guarantee is offered. ## Security boundary The plugins generate local text and structural preview files. They reject unsafe paths, symlink escapes, accidental overwrites, malformed specifications, active preview content, unsafe optional-renderer output, and unsafe archive entries. They do not operate a hosted service, authenticate users, send telemetry, automate desktop applications, execute generated model code, or guarantee that a downstream renderer, compiler, simulator, or importer is safe. Users must review generated source before executing it with external software and must apply appropriate sandboxing and access controls to sensitive inputs.
SHA-256: b6f4768bc0c6198f7a2e11b86bee16519b7a9b14c96f5cfb1f2abd0261644e28