Skip to content

Security: hazennik/asi

Security

SECURITY.md

Security Policy

Supported Versions

Currently supported:

  • ASI v0.1 (Node SDK)

Future versions will be listed here as they are released.


Reporting a Vulnerability

If you discover a security vulnerability in:

  • The ASI specification
  • The Node reference SDK
  • Test vectors
  • Example bundles

Please report it privately before public disclosure.

Contact

Email: security@asi-spec.org
(Replace with actual contact before public launch)


Disclosure Policy

  • We will acknowledge receipt within 48 hours.
  • We will assess severity and provide a remediation timeline.
  • Critical vulnerabilities will be patched immediately.
  • Credit will be given to reporters unless anonymity is requested.

Scope

Security reports should relate to:

  • Cryptographic misuse
  • Canonicalization flaws
  • Signature validation errors
  • Identity spoofing vulnerabilities
  • Bundle verification bypasses
  • Replay attack weaknesses

Reports about ecosystem misuse (malicious but correctly signed skills) are out of scope for ASI v0.1, as ASI verifies identity, not intent.

There aren't any published security advisories