- Fix URL validation to check for https:// or http:// prefixes instead of partial string matching which could be bypassed - Add path traversal protection in skill remove command to reject .., /, and verify canonical path is inside the skills directory |
||
|---|---|---|
| .. | ||
| mod.rs | ||
| symlink_tests.rs | ||