Skip to content

Security: GoPlusSecurity/skills

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously at GoPlus Security. If you discover a security vulnerability in this project, please report it responsibly.

How to Report

Please DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via one of the following methods:

  1. Email: Send details to security@gopluslabs.io
  2. GoPlus Security Platform: Report through GoPlus Security

What to Include

Please include the following information in your report:

  • Type of vulnerability
  • Full path to the affected file(s)
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code (if possible)
  • Impact assessment

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Target: Based on severity

Severity Levels

Level Description Target Resolution
Critical Immediate threat to users 24-48 hours
High Significant security impact 7 days
Medium Limited security impact 30 days
Low Minimal security impact 90 days

Scope

This security policy applies to:

  • All code in this repository
  • Skills and plugin configurations
  • Documentation that may expose sensitive patterns

Out of Scope

Security Best Practices

When using these skills:

  1. Never commit API keys - Use environment variables
  2. Validate all inputs - Don't trust external data blindly
  3. Review before execution - Always review AI-generated code
  4. Keep dependencies updated - Regularly update goplus-mcp

Acknowledgments

We appreciate the security research community's efforts in responsibly disclosing vulnerabilities. Contributors who report valid security issues will be acknowledged (with permission) in our security advisories.

Thank you for helping keep GoPlus Security Skills safe!

There aren’t any published security advisories