RouteKit Shell (rks) is currently in early development. Security fixes are applied to the latest version on the main branch only.
Please do not report security vulnerabilities through public GitHub issues.
To report a vulnerability, email [email protected] with the subject line [rks] Security Vulnerability. Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (or proof-of-concept code if applicable)
- Any suggested mitigations you have identified
You can expect an acknowledgment within 72 hours and a status update within 7 days.
This policy covers the rks MCP server, CLI, and governance hooks in this repository. It does not cover third-party dependencies — please report those to the respective upstream projects.
We follow responsible disclosure. Once a fix is available we will coordinate a disclosure timeline with the reporter. We will credit reporters who wish to be named in the release notes.