#1522·kirara-ai

Security: could you enable a private channel so I can report a workflow issue? / 能否开启私密渠道以便报告一个 workflow 安全问题?

Author: kobihikriCreated Jul 29, 2026Updated Jul 29, 2026

Hello, and thank you for Kirara AI.

I think I have found a security issue in one of the repository's GitHub Actions workflows, and I would like to report it privately rather than describe it in a public issue — a public description would effectively be a disclosure before you have had a chance to act.

I could not find a private channel for the project: there is no SECURITY.md, and GitHub's private vulnerability reporting does not appear to be enabled. Could you either:

  • enable private vulnerability reporting (Settings → Security → Private vulnerability reporting), or
  • add a SECURITY.md with a contact, or
  • share a security contact (email / other) here,

so I can send the details privately? Once a channel exists I will send the full write-up, which includes the affected file, the exact lines, and a suggested fix. It is a workflow-configuration issue rather than anything in the deployed bot, and I have not run anything against your infrastructure.

Thank you for your time.


你好,感谢你们开发 Kirara AI。

我认为在仓库的某个 GitHub Actions workflow 中发现了一个安全问题,希望私下报告,而不是在公开 issue 中描述——公开描述相当于在你们处理之前就披露了漏洞。

我没有找到私密的报告渠道:仓库没有 SECURITY.md,也似乎没有启用 GitHub 的私密漏洞报告功能。能否请你们:

  • 启用 Private vulnerability reporting(Settings → Security),或
  • 添加带联系方式的 SECURITY.md,或
  • 在此处提供一个安全联系方式(邮箱等)?

有了渠道之后,我会把完整说明(涉及的文件、具体行号和修复建议)私下发给你们。这是一个 workflow 配置问题,与已部署的机器人本身无关,我也没有对你们的基础设施进行任何测试。

谢谢!


Disclosure: I used an AI assistant to help find this and to draft this message; I verified the workflow file myself. / 说明:我借助了 AI 助手来发现问题并起草此消息,workflow 文件由我本人核实。