Skip to content

Security: StaticHumStudio/ai-project-signal-skill

SECURITY.md

Security Policy

Supported version

Security fixes are made on the latest main branch. Older commits and forks are not maintained by Static Hum Studio.

Report a vulnerability privately

Please do not open a public issue for a suspected vulnerability.

Use a private GitHub security advisory. If that form is unavailable, email static@statichum.studio with the subject Signal security report.

Include the affected file or route, a minimal reproduction, the likely impact, and any safe remediation you have already tested. Do not include live credentials, personal data, or copied private material.

You should receive an acknowledgment within seven days. Please allow time for a fix before publishing details.

Research disagreements, stale source claims, and general quality concerns are important, but they are not security vulnerabilities. Those can use a normal GitHub issue.

There aren't any published security advisories