Do not open a public issue for a vulnerability, credential exposure, hidden network behavior, destructive action, or privacy problem.
Use GitHub's private security advisory flow for this repository. Include:
- the action name and stable ID;
- the affected catalog revision and ActionClip version;
- a minimal, non-sensitive reproduction;
- the observed destination, command, or side effect;
- the expected behavior and suggested mitigation, if known.
Never include API keys, tokens, private selected text, personal documents, or customer data in a report.
Security fixes are applied to the current marketplace catalog and, when feasible, the most recent catalog compatible with the latest public ActionClip release. A vulnerable action may be unpublished or disabled before a replacement is ready.