Files

16 lines
726 B
Markdown

# Security Policy
## Reporting a vulnerability
Please do not disclose vulnerabilities, credentials, tokens, or private account data in a public issue.
Use GitHub's private vulnerability reporting for the implementation repository:
https://github.com/sandbaseai/cli/security/advisories/new
Include the affected version, reproduction steps, expected and observed behavior, and the minimum proof needed to demonstrate impact. Remove credentials and personal data from logs and screenshots.
## Scope
This repository packages the official SandBase Codex plugin. The CLI and MCP implementation are maintained in [sandbaseai/cli](https://github.com/sandbaseai/cli), so implementation vulnerabilities should be reported there.