Skip to content

Security: XenoExia/opencode-workflow-playbook

Security

SECURITY.md

Security Policy

Scope

This repository is primarily documentation, templates, and workflow guidance.

That said, it touches areas that can affect real environments:

  • configuration templates
  • instruction files
  • MCP setup guidance
  • operational workflow patterns

Reporting a security concern

If you believe a documented pattern, template, or example introduces a security risk, please avoid posting sensitive details publicly in an issue.

Instead, open a private report through the repository maintainer's preferred security contact method, or open a minimal public issue without secrets if the concern is low-risk and primarily documentation-related.

What to include

  • the affected file or section
  • the risky behavior or assumption
  • the likely impact
  • a safer alternative, if known

Expectations

Please do not include tokens, credentials, private traces, or copied secrets in reports or pull requests.

There aren’t any published security advisories