Skip to content

Security: DXBMARK/x32-m32-osc-skill

Security

SECURITY.md

Security Policy

Supported version

Version Supported
1.1.x Yes
1.0.x Security fixes only

Scope

This repository is a standalone Agent Skill and offline validation toolkit. It contains no MCP server, no network listener, no live OSC sender, no API credentials, and no hosted endpoint.

Security issues still matter because the Skill can inform code generation and remote-control planning. Report problems involving:

  • a command or address that bypasses uncertainty quarantine
  • unsafe risk classification
  • invalid OSC encoding or decoding
  • a validator that permits network-sender code
  • a hidden external URL or schema dependency
  • a hard-coded repository, endpoint, credential, token, or private IP
  • source attribution or provenance errors
  • a packaging process that includes source PDFs or unrelated implementation code

Reporting

Do not open a public issue for a suspected vulnerability that could lead to unsafe live-console control. Use GitHub private vulnerability reporting when enabled, or email:

support@dxbmark.com

Include:

  • affected version and file
  • reproduction steps
  • expected and actual behaviour
  • operational impact
  • whether live hardware was involved
  • logs with credentials and private addresses removed

Safety boundary

The Skill must remain offline by default. Any separate live executor must provide its own authentication, authorisation, network isolation, operator approval, rate limits, emergency stop, verification, rollback, and audit controls.

Disclosure

DXBMARK will acknowledge a complete report, assess severity, prepare a fix, and coordinate disclosure. Do not test unknown writes on production or live-show hardware.

There aren't any published security advisories