Skip to content

Security: Loffee5422/super-study

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest released version and the main branch.

Reporting a vulnerability

Do not open a public Issue for a vulnerability or accidental credential exposure. Use GitHub private vulnerability reporting and include:

  • the affected version or commit;
  • the smallest safe reproduction;
  • expected impact;
  • any proposed mitigation;
  • whether credentials or private learning data may have been exposed.

Please avoid accessing data that is not yours, disrupting systems, or publishing details before a fix is available.

Security boundaries

Super Study can inspect user-provided repositories, folders, documents, and URLs. The Skill requires those source projects to remain read-only unless the user explicitly authorizes a change. Obsidian write operations require recorded consent, and local configuration is excluded from the repository.

For cybersecurity learning, only use systems you own or are explicitly authorized to test, prefer isolated labs, and avoid destructive or persistence-oriented activity.

There aren't any published security advisories