| Version | Supported |
|---|---|
| 1.1.x | Yes |
| 1.0.x | Security fixes only |
This repository is a standalone Agent Skill and offline validation toolkit. It contains no MCP server, no network listener, no live OSC sender, no API credentials, and no hosted endpoint.
Security issues still matter because the Skill can inform code generation and remote-control planning. Report problems involving:
- a command or address that bypasses uncertainty quarantine
- unsafe risk classification
- invalid OSC encoding or decoding
- a validator that permits network-sender code
- a hidden external URL or schema dependency
- a hard-coded repository, endpoint, credential, token, or private IP
- source attribution or provenance errors
- a packaging process that includes source PDFs or unrelated implementation code
Do not open a public issue for a suspected vulnerability that could lead to unsafe live-console control. Use GitHub private vulnerability reporting when enabled, or email:
support@dxbmark.com
Include:
- affected version and file
- reproduction steps
- expected and actual behaviour
- operational impact
- whether live hardware was involved
- logs with credentials and private addresses removed
The Skill must remain offline by default. Any separate live executor must provide its own authentication, authorisation, network isolation, operator approval, rate limits, emergency stop, verification, rollback, and audit controls.
DXBMARK will acknowledge a complete report, assess severity, prepare a fix, and coordinate disclosure. Do not test unknown writes on production or live-show hardware.