Skip to content

Security: samibajwaisking/Token-Optimizer-Skill

Security

SECURITY.md

Security Policy

Scope

This repository contains a Claude AI Skill — a set of Markdown-based prompt engineering files. There is no executable code, no server, and no user data collection.

Security concerns in this context include:

  • Prompt injection patterns that could manipulate Claude into harmful behavior
  • Instructions that bypass Claude's safety guidelines
  • Misuse of system prompt templates for deceptive or malicious applications
  • License violations or unauthorized redistribution

Reporting a Vulnerability or Misuse

If you discover content in this skill that:

  • Could be used to manipulate AI systems in harmful ways
  • Contains instructions that violate Anthropic's usage policies
  • Enables misuse, deception, or harm when applied to real users

Please do NOT open a public GitHub issue.

Report it privately via:

Include in your report:

  1. Which file and which specific content is concerning
  2. How it could be misused
  3. Your suggested fix (optional but appreciated)

Response Timeline

Stage Timeframe
Acknowledgement Within 48 hours
Initial assessment Within 5 days
Fix or response Within 14 days

Responsible Disclosure

We follow responsible disclosure principles. If you report a valid concern privately and allow reasonable time to respond, we will:

  • Credit you in the CHANGELOG (if you want)
  • Not take legal action for good-faith security research

Out of Scope

The following are NOT security vulnerabilities for this project:

  • Claude giving unexpected or lower-quality outputs (that's a prompt improvement request)
  • Disagreements with token savings claims (open an issue or PR instead)
  • General questions about how Claude works

Security policy maintained by Sami Bajwa

There aren't any published security advisories