Skip to content

Security: likecheng110/osac-bench

Security

SECURITY.md

Security policy

Public-data boundary

Never commit credentials, bearer tokens, private keys, tenant identifiers, raw model responses, private prompts, evaluator-private goldens, mutation bundles, local absolute paths, VM images, or real incident records.

Public reports may contain redacted fingerprints, content digests, aggregate usage, deterministic checker results, and classified failures.

Reporting a vulnerability

Report security-sensitive issues privately to the repository maintainer contact when one is published. Do not open a public issue containing an active credential, exploitable infrastructure detail, private fixture, or raw incident data.

Operational safety

OSAC-Bench fixtures are synthetic. Tool implementations must use allowlisted operations, bounded output, explicit roots/endpoints, and a controlled test environment. The benchmark does not authorize access to third-party systems.

There aren't any published security advisories