Tastemaker is a local skill. It is Markdown and Python scripts that run on your machine, with no hosted backend and no accounts. The main things worth reporting are a script that could be tricked into writing outside its output folder, or a fetch helper that could be pointed somewhere unsafe.
Please do not open a public issue for a security problem.
Report it privately through GitHub's security advisory form, or by email to codeswithroh@gmail.com.
Include what you found, how to reproduce it, and the impact you expect. You will get a response as soon as possible.
This project moves fast and always ships from main. Fixes land on main. Please test against the latest version before reporting.