Skip to content

Security: HiTecHelpLLC/l1ght5p33d-workflows

SECURITY.md

Security

Treat workflow files, descriptions, effects and claimed verification as untrusted until reviewed. A hash detects content drift; it does not prove author identity, safe intent or that a workflow is suitable for your machine.

The curator index is not signed and is not directly installable as a signed runtime catalog. Detached THEBEST review attestations bind exact versioned files and test evidence; verify them against a separately trusted public key as described in SIGNING.md. This repository contains no private signing key or persistent network service. Downloads and signatures do not grant permission or execute workflows.

Do not submit secrets, cookies, profiles, private screenshots or personal media. Report vulnerabilities privately through the repository owner's GitHub security reporting channel when enabled. If unavailable, ask the maintainer for a private channel without posting exploit details or sensitive data publicly.

The synthetic qualification script is opt-in developer tooling. It launches only the fixed local fixture and a temporary browser context. Do not modify it to run untrusted downloads. Runtime installations should use the recorded upstream commit and undergo the dependency checks of the parent project.

There aren't any published security advisories