If you discover a security vulnerability in ag3ntwerk, please do not open a public issue.
Instead, report it privately by emailing chris@gozerai.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation plan within 7 days for critical issues.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
The following are in scope for security reports:
- Authentication and authorization bypasses
- Injection vulnerabilities (SQL, command, template)
- Secrets or credentials exposed in code or logs
- Insecure defaults that could lead to data exposure
- Dependency vulnerabilities with a clear exploitation path
We follow coordinated disclosure. We will credit reporters in release notes unless anonymity is requested.