Skip to content

Security: HKUSTDial/DataMagic

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main Yes
0.1.x Yes

This repository publishes documentation and the datamagic skill for coding agents. The hosted product at datamagic.chat is operated separately.

Reporting a Vulnerability

Please do not open a public GitHub issue for security reports.

Prefer one of these private channels:

  1. GitHub private vulnerability reporting: Open a security advisory
  2. If that form is unavailable, email the maintainers through the HKUST Dial Lab contact listed on the project homepage

Include:

  • A description of the issue and its impact
  • Reproduction steps or a proof of concept
  • Affected files, skill instructions, or workflow names
  • Whether the issue is in this repository, the skill package, or the hosted product

Response

We aim to acknowledge reports within 3 business days and to share a remediation plan or status update within 7 days. Critical issues that affect users of the skill or plugin packaging are prioritized first.

Please give us a reasonable window to patch before any public disclosure.

There aren't any published security advisories