| Version | Supported |
|---|---|
| 3.0.x | Yes |
| 2.0.x | Security fixes only — upgrade to v3.0 |
| 1.0.x | No — end of life, upgrade to v3.0 |
If you discover a security vulnerability in this project's code or scripts, do NOT open a public issue.
Report it privately via one of:
- GitHub Security Advisories — Submit a private report
- GitHub private message — Contact the repository maintainer directly
- Description of the vulnerability
- Affected file(s) and line numbers if applicable
- Steps to reproduce
- Potential impact (what an attacker could do)
- Suggested fix or mitigation (if you have one)
| Stage | Target |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 7 days |
| Fix release (critical) | Within 30 days |
| Fix release (medium/low) | Within 90 days |
This skill collection is designed for authorized security testing, research, and education only.
Before using any tool or script in this collection, you must:
- Have written authorization from the system owner before testing any system you do not personally own
- Comply with all applicable laws (Computer Fraud and Abuse Act, Computer Misuse Act, GDPR, etc.)
- Operate only within explicitly defined scope (IP ranges, domains, environments)
- Use offensive tools only in isolated, controlled environments when testing your own systems
- Report vulnerabilities discovered during authorized testing to the affected parties through responsible disclosure
Skills with offensive capabilities (03-exploit-development, 14-red-team-ops) require authorization verification before Claude provides operational assistance. This is enforced in the SKILL.md authorization gates.
- Penetration testing with a signed Statement of Work
- Bug bounty programs (in-scope targets only)
- CTF competitions
- Security research in isolated lab environments
- Defensive security — hardening, detection engineering, incident response
- Unauthorized access to any computer system
- Targeting systems outside your authorized scope
- Distributing discovered vulnerabilities without coordinated disclosure
- Using scripts to harm, disrupt, or spy on individuals or organizations
This policy covers:
- The skill collection scripts and code
- The SKILL.md instruction files
- Documentation and configuration templates
This policy does NOT cover:
- Third-party tools referenced by the skills (Nmap, Volatility, etc.)
- Systems or networks tested using these skills
- User modifications to the scripts or SKILL.md files
Responsible reporters will be credited in the release notes (unless they prefer anonymity).