If you discover a security vulnerability in this template, please report it responsibly:
- Do NOT open a public issue
- Email the maintainer directly or use GitHub's private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix timeline: Depends on severity
This template contains configuration files, not application code. Security concerns typically involve:
- Exposed secrets in example files
- Unsafe default permissions
- Vulnerable MCP server configurations
- Hook scripts with security issues
- Never commit
.envfiles - They're gitignored for a reason - Review hook scripts before enabling them
- Audit MCP servers you enable - they have system access
- Keep permissions minimal in settings.json