Skip to content

Security: AgentBreach/absec

Security

SECURITY.md

Security Policy

Supported versions

We support the latest published @agentbreach/absec and @agentbreach/absec-core minor releases.

Reporting a vulnerability

Email security@agentbreach.com with a description, reproduction steps, and impact. Do not open a public GitHub issue for security vulnerabilities.

Product safety defaults

  • No Agent Breach account or cloud API is required.
  • Telemetry is off unless ABSEC_TELEMETRY=1.
  • absec headers refuses non-localhost URLs unless --allow-remote is set.
  • Findings may include redacted secret-like strings; treat reports as sensitive.

There aren't any published security advisories