Please report suspected vulnerabilities privately.
- Preferred: GitHub private vulnerability reporting for this repository.
URL:
https://github.com/bohewu/agents_pipeline/security/advisories/new - Fallback: contact the maintainer privately on GitHub and include the affected files, impact, and reproduction details.
Do not open a public issue for an unpatched vulnerability.
Examples include:
- token, credential, or secret exposure
- insecure handling of local auth files or provider reports
- supply-chain verification bypasses in installers or remote content flows
- unsafe remote fetch/install behavior that can execute or trust unexpected content
- path traversal, arbitrary file overwrite, or unsafe cleanup behavior in scripts/plugins/tools
- privacy leaks caused by unexpectedly printing account metadata or sensitive identifiers
If you are unsure whether something is security-relevant, report it privately anyway.
- Never commit live tokens, auth JSON, premium-usage reports, or copied provider payloads.
- Prefer pinned release assets and checksums over mutable
mainbootstrap flows. - Runtime installers replace only marker-owned namespaced support trees; do not remove the ownership check to make an unmarked target install succeed.
- Treat generated checkpoint/status artifacts as potentially sensitive because prompts, paths, errors, and evidence references may contain project details.
- Review runtime model/profile overrides before distribution; keep credentials and provider account metadata out of neutral manifests.
- Keep error messages helpful, but do not print full tokens, cookies, refresh payloads, or raw credential blobs.
- Initial acknowledgement target: within 3 business days.
- Triage/update target: weekly until the issue is resolved or ruled out.
- If a fix is needed, the goal is to ship the smallest safe patch first, then follow up with broader hardening if necessary.
Please wait for a maintainer confirmation before public disclosure. Once fixed, we can coordinate a changelog/security note as appropriate.