Skip to content

Security: HarrisonWard/Tabletop-Library

SECURITY.md

Security

This is an exercise library. No code to exploit, two things worth reporting fast anyway.

Guidance that would make a real incident worse. People practice from these packs, and practice becomes reflex. If a scenario teaches a dangerous reflex, evidence destruction, a notification clock misstatement, a safety call framed wrong in the OT pack, open an issue. That bug fires during someone's worst day, and it jumps the queue.

Anything that looks client-identifiable. Every scenario should read as a pattern, never as a disguised real event. If one reads like a true story with the names filed off, do not open a public issue. Use GitHub's private vulnerability report on this repo, or the contact on my profile, and it gets handled quietly and quickly.

No bounty program. The reward is a room somewhere finding its gaps on a Tuesday afternoon instead of during the real thing.

There aren't any published security advisories