Security fixes are applied to the latest released version of the toolkit. Users should update their marketplace and reinstall the plugin before reporting an issue that may already be fixed.
Do not report suspected vulnerabilities in a public issue, discussion, or pull request. Use GitHub private vulnerability reporting for this repository and include:
- the affected plugin, skill, script, or MCP configuration;
- the expected and observed behavior;
- reproduction steps or a minimal proof of concept;
- the potential impact; and
- any suggested mitigation.
Do not include real credentials, customer data, organization configuration, or personal data. Use sanitized examples.
The maintainers will assess the report, coordinate remediation, and disclose the issue when a fix or mitigation is available. Vulnerabilities in epilot's hosted platform or APIs that are unrelated to this repository should be reported through epilot's established security channels instead.