github sickn33/antigravity-awesome-skills v12.2.1
v12.2.1 "Security Scan Follow-up"

6 hours ago

[12.2.1] - 2026-06-07 - "Security Scan Follow-up"

Patch release for the June 7 security scan remediation after 12.2.0.

Security

  • Hardened user-thoughts runtime file handling against symlink traversal and realpath escapes inside .ustht/.
  • Fixed tar archive validation to prefer PAX path / linkpath headers before GNU long-name headers.
  • Replaced risky documentation examples for unquoted Git branches, placeholder git add, predictable /tmp installer paths, token-printing Vercel commands, and unsafe JSON-LD injection.
  • Removed public Google and Bing site-verification tokens from the web app.
  • Raised risk labels and plugin metadata for external-code and remote-execution skills, including runapi-cli, open-dynamic-workflows, and polis-protocol.

Improvements

  • Marked 2slides-ppt-generator plugin setup as manual with declared Python requirements.
  • Fixed broken plugin bundle links and the mobile plugin skill list.
  • Regenerated plugin compatibility reports, skill indexes, web assets, and plugin mirrors after the remediation.

Don't miss a new antigravity-awesome-skills release

NewReleases is sending notifications on new releases.