Skip to content

Security: William189189/ALAMAK

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Email: security@terrene.foundation

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment: Within 48 hours of report
  • Initial assessment: Within 5 business days
  • Resolution target: Within 30 days for critical issues

Scope

This repository contains COC (Cognitive Orchestration for Codegen) templates for Claude Code. Security concerns typically involve:

  • Sensitive data exposure in template files
  • Unsafe patterns in agent instructions or rules
  • Path traversal or injection risks in hook scripts

Disclosure

We follow coordinated disclosure. Please do not publicly disclose vulnerabilities until we have issued a fix and provided reasonable time for users to update.

Supported Versions

Only the latest release on the main branch is actively supported with security updates.

There aren't any published security advisories