Skip to content

Security: use-agent-os/agent-os

SECURITY.md

Security Policy

Supported Versions

Security fixes are evaluated against the current main branch and the latest public release. Older snapshots may receive a fix only when the affected code is still present in the current release line.

Reporting a Vulnerability

Do not open a public issue with vulnerability details, exploit steps, credentials, provider tokens, local transcripts, or account identifiers.

Submit suspected vulnerabilities through GitHub private vulnerability reporting. This repository has private reporting enabled so reports can be triaged and discussed with maintainers without public disclosure.

If you cannot access the private report form, open a minimal public issue asking for a secure maintainer contact path. Do not include technical details in that issue.

Helpful reports include:

  • Affected version or commit.
  • A concise description of the vulnerable behavior.
  • Reproduction steps using placeholders instead of real credentials.
  • Expected impact and any known mitigations.

Audit Reports and Scanner Output

Do not submit audit reports, scanner output, or security review documents as pull requests. A report pinned to a commit goes stale in the tree within weeks with nothing to keep it honest, and a document committed to this repository reads as maintainer-endorsed regardless of who wrote it.

Route those findings through the private advisory link above. We triage every finding against main and reply with a per-finding verdict.

There is no bug bounty or paid reward program for AgentOS, and none is planned. Researchers whose reports lead to a fix are credited in the release notes for that fix, under whichever name they prefer.

Handling

Maintainers will acknowledge valid reports, triage severity, prepare a fix on a restricted branch when appropriate, and publish public details after a release or mitigation is available.

There aren't any published security advisories