This policy applies to OpenlyUseful.org, OpenlyUseful.com, and every repository in the Openly-Useful organization unless a repository ships its own SECURITY file. It also covers publicly released Openly Useful skills, MCP servers, packages, and provider artifacts that identify the canonical publisher record.
Openly Useful is one brand with two public homes: OpenlyUseful.com for Studio work and OpenlyUseful.org for Open Source work, policies, and publisher identity. Openly Useful LLC is the planned legal entity, with status formation-pending; this policy does not represent it as formed or active.
- Email: hello@openlyuseful.org with the subject line
SECURITY. - GitHub: where a repository shows "Report a vulnerability" under its Security tab, private vulnerability reporting is enabled and preferred.
Please include the affected repository, a description of the issue, reproduction steps or a proof of concept, and the impact you believe it has.
- We will make a reasonable effort to acknowledge reports and provide progress updates, but no guaranteed response time is offered.
- We will credit you in the fix when appropriate unless you ask otherwise.
- Please give us reasonable time to fix an issue before public disclosure. We default to coordinated disclosure and will agree on a timeline with you.
OpenlyUseful.org, OpenlyUseful.com, public Openly-Useful repositories, and released publisher-identified skills, MCP servers, packages, and provider artifacts are in scope. Third-party services, customer systems, social engineering, denial-of-service activity, destructive testing, and infrastructure or accounts you do not own are out of scope. Prefer static analysis, local reproduction, and the least invasive proof possible.