Please do not disclose API keys, tokens, personal data, or private customer material in Issues or pull requests.
Report suspected vulnerabilities privately to the Agent Body security team through the security contact published by your Agent Body deployment. Include a concise description, affected Skill or REST API path, reproduction steps, and impact. Allow the team reasonable time to investigate before public disclosure.
Skill files must not contain credentials or instructions that bypass authentication, authorization, rate limits, or privacy controls.