skillgate is pre-1.0. Security fixes land on the latest published 0.x release on npm
(@reneza/skillgate). Please upgrade to the latest version before reporting.
Please do not open a public issue for security problems.
Report privately through GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab). If that is unavailable, email the maintainer listed on the npm package page.
When reporting, include:
- the version (
skillgate --version) and how you run it (npx / npm / CI / pre-commit), - a minimal
.skillgate/done.yamland repo layout that reproduces the issue, - the impact you observed.
You can expect an initial acknowledgement within a few days. Fixes are released as a
new patch version with a note in CHANGELOG.md.
skillgate runs command-type gates, which execute the shell command you put in your
own done.yaml. Treat a done.yaml from an untrusted source the same way you would
treat any script in that repo — review it before running skillgate check.
The experimental private-pass commands create a BBS signing key. The default private
key is mode 0600 and added to .skillgate/.gitignore, but filesystem permissions and
gitignore are not an isolation boundary. For a credible third-party attestation, keep
the private key on a separate gate server the coding agent cannot access, pin its public
key out of band, and rotate it after suspected compromise. A party holding that private
key can issue a pass attestation without running Skillgate.