Skip to content

Security: ngctro/pi-pstack

SECURITY.md

security policy

supported versions

version supported
latest tag yes
main yes
older tags no

reporting a vulnerability

pstack ships skills (markdown instructions) and small scripts that agents execute with your permissions. A malicious skill is as dangerous as malicious code — review content before installing, same as any pi package.

Please report vulnerabilities privately via GitHub private vulnerability reporting. Do not open a public issue for anything exploitable.

Include: the affected file/skill, how an agent could be made to misbehave, and a minimal reproduction if possible.

You'll get an acknowledgment within a few days, and a fix or mitigation timeline once triaged.

There aren't any published security advisories