Please report security vulnerabilities privately — do not open a public issue.
Use GitHub's private vulnerability reporting for this repository (Security tab → "Report a vulnerability"). This opens a private draft advisory visible only to maintainers until it's resolved.
Include:
- A description of the vulnerability and its impact
- Steps to reproduce (or a proof of concept)
- The affected version/commit
We'll acknowledge reports and work with you on a fix and coordinated disclosure timeline.
Only the latest release is supported. Since website-builder ships as a downloaded skill suite rather than a running service, please update to the latest release before reporting an issue that may already be fixed.