Skip to content

Security: raphaelmarra/method-forge

Security

SECURITY.md

Security Policy

Method Forge is primarily a documentation and agent-skill repository. Security concerns may still include exposed credentials, unsafe automation instructions, dependency or workflow compromise, malicious links, and guidance that crosses a declared authority boundary.

Reporting

Do not open a public issue for an exposed secret or an exploitable repository vulnerability. Use GitHub's private vulnerability reporting feature when available, or contact the repository owner privately through GitHub.

Include the affected path, impact, reproduction conditions, and a safe remediation suggestion. Do not include real credentials or unnecessary personal data.

Scope

Supported security reports concern the current default branch and active releases. Methodological disagreement, stale external versions, and broken citations should normally use issues unless disclosure would create an immediate risk.

There aren't any published security advisories