Build Like This contains the published mstack CLI, AI-environment adapters, documentation, and reusable templates. Security reports may concern the executable packages, unsafe generated instructions, path or file handling, dependency integrity, leaked credentials, or malicious links.
Please report a suspected vulnerability privately through GitHub's security advisory feature rather than a public issue. Include the affected package or document, impact, safe reproduction steps, and a remediation if known.
mstack is expected to preserve user-owned repository content and avoid exposing local secrets. A path that overwrites files unexpectedly, escapes the target repository, executes untrusted input, weakens agent permissions, or includes sensitive data in diagnostics should be treated as a security issue.
Do not include real credentials, private repository content, personal data, or production endpoints in a report. Use synthetic examples and redact local paths where possible.