Skip to content

Security: SDK-E/workforce

Security

SECURITY.md

Security policy

Report suspected vulnerabilities privately to the repository maintainers through GitHub's private vulnerability reporting feature. Do not include secrets, exploit payloads, customer data, or proof-of-concept artifacts in public issues.

Include affected versions, reproduction steps, expected versus actual behavior, and any relevant sanitized logs. We will acknowledge reports, assess impact, and coordinate a fix before public disclosure.

The most sensitive areas are Docker isolation, egress policy, secret scope, artifact extraction, terminal sanitization, MCP integration, and company/project isolation.

There aren't any published security advisories