Report vulnerabilities through GitHub's private vulnerability reporting. Do not open a public issue or pull request for an undisclosed vulnerability.
Include the affected skill or repository component, impact, reproduction steps, and a suggested mitigation when possible. Never include live credentials, customer data, or other sensitive material.
This policy covers skill instructions and scripts, dependency or supply-chain
risks, repository automation, and ways a skill could access or modify more than
it discloses. Vulnerabilities in the HeyGen or HyperFrames products themselves
should be reported to security@heygen.com.
Only the current default branch is supported. Maintainers will coordinate disclosure after a fix or mitigation is available.