feat: publish Sandwich Hime tooling preview
Publish the exact sanitized Agent Skill and VS Code preview source tree with independent license boundaries, deterministic provenance manifests, and no private development history. Material design and implementation assistance was provided by OpenAI Codex. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
+18
@@ -0,0 +1,18 @@
|
||||
<!-- SPDX-License-Identifier: AGPL-3.0-only -->
|
||||
|
||||
# Security policy
|
||||
|
||||
Report suspected vulnerabilities privately to security@sandwichhime.com.
|
||||
Include the affected version, platform, reproduction steps, and expected
|
||||
impact without secrets or unnecessary personal data. Expect a best-effort
|
||||
acknowledgement within three business days, initial triage within seven, and
|
||||
an update at least every fourteen days while work remains open.
|
||||
|
||||
The preview has no bug bounty. Good-faith research that avoids privacy harm,
|
||||
service disruption, credential access, persistence, and public disclosure
|
||||
before a reasonable remediation period is welcome.
|
||||
|
||||
The Agent Skill is instruction text. The VS Code extension starts a locally
|
||||
installed Hime-san only inside a trusted workspace and never downloads or
|
||||
upgrades it. Syntax highlighting remains available in untrusted workspaces;
|
||||
all subprocess-backed features are disabled.
|
||||
Reference in New Issue
Block a user