Skip to content

Security: Lightning-AI/skills

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public GitHub issue for security problems.

Email security@lightning.ai with:

  • what you found and where (skill name, file, command)
  • steps to reproduce it
  • the impact you expect (for example: leaked credentials, unintended spend, code running where it shouldn't)

We will acknowledge your report, keep you updated while we investigate, and credit you in the fix if you'd like.

Scope

In scope: the skills, scripts and plugin manifests in this repository, for example a skill that leaks an API key, runs commands the user didn't ask for, or spends money without asking first.

Vulnerabilities in the Lightning AI platform itself or in the lightning-sdk package are also welcome at the same address.

There aren't any published security advisories