Initial release v1.0.0
Open-source marketplace for AI Agent skills. Features: - Next.js 15 web app with i18n (en/fa) - CLI tool for skill installation (npx skillhub) - GitHub crawler/indexer with multi-strategy discovery - Security scanning for all indexed skills - Self-hostable with Docker Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
65
SECURITY.md
Normal file
65
SECURITY.md
Normal file
@@ -0,0 +1,65 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
| Version | Supported |
|
||||
|---------|-----------|
|
||||
| Latest | Yes |
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in SkillHub, please report it responsibly.
|
||||
|
||||
**Do NOT open a public GitHub issue for security vulnerabilities.**
|
||||
|
||||
### How to Report
|
||||
|
||||
1. **Email:** Send details to [dev@airano.ir](mailto:dev@airano.ir)
|
||||
2. **Subject:** `[SECURITY] Brief description`
|
||||
3. **Include:**
|
||||
- Description of the vulnerability
|
||||
- Steps to reproduce
|
||||
- Potential impact
|
||||
- Suggested fix (if any)
|
||||
|
||||
### What to Expect
|
||||
|
||||
- **Acknowledgment:** Within 48 hours
|
||||
- **Assessment:** Within 7 days
|
||||
- **Fix timeline:** Depends on severity (critical: 24-72h, high: 1-2 weeks)
|
||||
|
||||
### Scope
|
||||
|
||||
The following are in scope:
|
||||
- SkillHub web application
|
||||
- SkillHub CLI (`skillhub` npm package)
|
||||
- SkillHub API endpoints
|
||||
- Indexer/crawler service
|
||||
|
||||
The following are out of scope:
|
||||
- Third-party services (GitHub, Meilisearch, Redis)
|
||||
- Issues in dependencies (report to upstream)
|
||||
- Social engineering attacks
|
||||
|
||||
## Security Measures
|
||||
|
||||
SkillHub implements the following security measures:
|
||||
|
||||
- **CSRF Protection:** All state-changing operations
|
||||
- **Input Sanitization:** Query parameters and user inputs
|
||||
- **Rate Limiting:** Per-endpoint rate limits
|
||||
- **Security Headers:** CSP, HSTS, X-Frame-Options
|
||||
- **Authentication:** GitHub OAuth via NextAuth.js
|
||||
- **Skill Scanning:** Automated security analysis (PASS/WARNING/FAIL) for all indexed skills
|
||||
- **SQL Injection Prevention:** Parameterized queries via Drizzle ORM
|
||||
|
||||
## Responsible Disclosure
|
||||
|
||||
We follow responsible disclosure practices. We ask that you:
|
||||
|
||||
- Allow reasonable time for a fix before public disclosure
|
||||
- Do not access or modify other users' data
|
||||
- Do not perform denial-of-service attacks
|
||||
- Act in good faith
|
||||
|
||||
We will credit reporters in our changelog (unless you prefer to remain anonymous).
|
||||
Reference in New Issue
Block a user