Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue containing credentials, local paths, task artifacts, worker state, or exploit details.
Security-sensitive areas include:
- Owner and attended-session authorization
- repository and allowed-root confinement
- provider-auth and quota snapshot sanitization
- subprocess argument construction
- task-scoped bindings and result sanitization
- fail-closed behavior for stale or missing evidence
The maintainers will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.