| version | supported |
|---|---|
| latest tag | yes |
| main | yes |
| older tags | no |
pstack ships skills (markdown instructions) and small scripts that agents execute with your permissions. A malicious skill is as dangerous as malicious code — review content before installing, same as any pi package.
Please report vulnerabilities privately via GitHub private vulnerability reporting. Do not open a public issue for anything exploitable.
Include: the affected file/skill, how an agent could be made to misbehave, and a minimal reproduction if possible.
You'll get an acknowledgment within a few days, and a fix or mitigation timeline once triaged.