| Version | Supported |
|---|---|
| 0.1.x | ✅ Yes |
AgentGuard is a security tool — we take vulnerabilities in our own code extremely seriously.
If you discover a security vulnerability, please do NOT open a public GitHub issue.
- Email: Send a detailed report to
Thomas.leon1707@gmail.com - Subject line:
[AgentGuard Security] <brief description> - Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if you have one)
- Acknowledgement: Within 48 hours
- Assessment: Within 7 days
- Fix/Disclosure: Within 30 days (coordinated with reporter)
- Escapes from the external Docker execution boundary
- Bypasses of the Docker network, filesystem, privilege or resource controls
- Bypasses of the AST or network pre-filters that weaken their documented policy
- Prompt injection attacks against the Semantic Judge
- Dependency vulnerabilities that affect AgentGuard's security guarantees
We will credit all responsible disclosures in our CHANGELOG and README (with your permission).
Yes, we appreciate the irony of a security tool needing a security policy. That's precisely why we have one. 🛡️