Only the latest commit on main is supported (this is a demonstration project).
If you discover a security vulnerability, please do not open a public issue.
Send a private email to: davide.ferigato@example.com (replace with real email).
We will acknowledge receipt within 48 hours and aim to resolve within 14 days.
- Always inspect third-party skills before installation – especially
allowed-toolsand scripts. - Run
scanner.pyin a sandbox if scanning untrusted code (e.g., container or isolated VM). - Never commit secrets –
.gitignoreexcludes.env,*.key, and*.pemby default. - Use
allowed-tools– this skill restricts scanner toRead,Grep,Globonly.
We follow a coordinated disclosure process:
- Reporter sends details privately.
- Maintainers confirm and address the issue.
- A fix is prepared and tested.
- Public disclosure with credits after fix is released.
We thank the community for helping keep MigraAPI secure. Security researchers are welcome to responsibly disclose findings.