Skip to content

Security: mukul975/Privacy-Data-Protection-Skills

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously, especially for a privacy-focused repository.

Preferred Method: GitHub Security Advisories

Report vulnerabilities through GitHub Security Advisories. This ensures confidential communication.

Alternative: Email

Send reports to security@privacy-skills.dev with subject line: [SECURITY] Brief description.

Response Timeline

Stage Target
Acknowledgment 48 hours
Initial assessment 7 days
Resolution target 30 days
Responsible disclosure 90 days

Scope

The following are in scope for security reports:

  • Inaccurate regulatory citations that could lead to compliance failures
  • Vulnerabilities in Python scripts (scripts/process.py files)
  • CI/CD pipeline security issues
  • Repository infrastructure vulnerabilities
  • Sensitive data exposure in skill templates

Out of Scope

  • The privacy regulations themselves
  • Third-party tools or platforms referenced in skills
  • Theoretical regulatory interpretation disagreements

Disclosure Policy

We follow a 90-day responsible disclosure timeline. If a fix requires more time, we will negotiate an extended timeline with the reporter.

Recognition

Security researchers who responsibly disclose vulnerabilities will be credited in CHANGELOG.md and in the relevant GitHub Security Advisory.

Contact

There aren’t any published security advisories