Files
sandwich-hime-tooling/SECURITY.md
T
gamertan 6df87bc958 feat: publish Sandwich Hime tooling preview
Publish the exact sanitized Agent Skill and VS Code preview source tree with independent license boundaries, deterministic provenance manifests, and no private development history. Material design and implementation assistance was provided by OpenAI Codex.

Signed-off-by: Cole Speelman <crspeelman@gmail.com>
2026-08-12 20:33:51 -04:00

19 lines
904 B
Markdown

<!-- SPDX-License-Identifier: AGPL-3.0-only -->
# Security policy
Report suspected vulnerabilities privately to security@sandwichhime.com.
Include the affected version, platform, reproduction steps, and expected
impact without secrets or unnecessary personal data. Expect a best-effort
acknowledgement within three business days, initial triage within seven, and
an update at least every fourteen days while work remains open.
The preview has no bug bounty. Good-faith research that avoids privacy harm,
service disruption, credential access, persistence, and public disclosure
before a reasonable remediation period is welcome.
The Agent Skill is instruction text. The VS Code extension starts a locally
installed Hime-san only inside a trusted workspace and never downloads or
upgrades it. Syntax highlighting remains available in untrusted workspaces;
all subprocess-backed features are disabled.