If you find a security issue in Coco, please do not open a public issue.
Instead, report privately:
- Open a draft security advisory on GitHub, or
- Email the maintainer directly (contact via GitHub profile)
Include:
- Description of the issue
- Steps to reproduce
- Affected files / skills / adapters
- Impact assessment (what an attacker could do)
- Suggested fix if you have one
We aim to respond within 7 days and ship a fix or mitigation within 30 days for confirmed issues. You'll be credited in the release notes if you wish.
Coco is a library of markdown artifacts and shell installers. The most likely security concerns:
| Concern | Severity | Notes |
|---|---|---|
| Malicious skill content (prompt injection) | medium | Skills are markdown; review before installing third-party additions |
Adapter install.sh symlink behavior |
low | Symlinks point only into the cloned repo; non-symlink files are left in place |
| Hardcoded credentials | high | Coco ships zero secrets; report any you find immediately |
| Supply-chain via plugin recommendations | medium | Skills must not `curl |
bin/coco-bootstrap.sh (the bash <(curl -fsSL ...) one-liner) clones the pinned
release tag (see PINNED_TAG in that script, kept in sync with package.json),
not floating main. It then pauses for interactive confirmation before installing —
it displays the cloned commit's hash, date, and message, and asks [y/N] before
running install.sh. This is a deliberate behavior change from the prior
zero-friction flow, added so users piping a remote script directly to their shell
get a chance to verify what they're about to run.
Pass --yes or set COCO_BOOTSTRAP_YES=1 to preserve the old unattended behavior for CI or
scripted installs. The npm CLI wrapper (bin/coco.js) uses the same tag pin.
- Issues in third-party AI tools (Claude Code, Cursor, Codex, etc.) — report to those projects
- Issues in external plugins listed in
docs/recommended-plugins.md— report to plugin authors - Issues in MCP servers — report to https://github.com/modelcontextprotocol/servers
We follow coordinated disclosure: report → acknowledge → fix → public disclosure. Please give us a reasonable window to ship a fix before publishing details.