chore(agents): defines a new AGENTS.md focused on reporting vulnerabilities#1680
Conversation
b39f029 to
b0e0a36
Compare
|
Hi @lukaszlenart, This looks good, but shouldn't It might also be useful to expand the instruction for PRs and ask the agent to first check if the PR solves some security issue. If that is the case the PR should not be submitted, but the issue should be reported. |
|
Hello @lukaszlenart, One suggestion: the pre-reporting steps, assessment checklist, and report requirements would also be useful to human researchers, not only AI agents. If the content moves to For Claude Code specifically, a Proposed structure:
|
|
As far I know Claude Code doesn't support AGENTS.md directly, anyway I can add a reference from CLAUDE.md to AGENTS.md and SECURITY.md. And I would keep AGENTS.md with a strong emphasis on security vulnerabilities reporting as I observe a large number of reports generated by Agents which basically overwhelms our abilities to analyze them. These days anyone with AI aspires to be a security specialist :\ |
|
@ppkarwasz @sepe81 I made some changes to treat SECURITY.md as the source of truth, updated AGENTS.md and CLAUDE.md to reference it. Let me know if this lean towards your expectations. |
Per @ppkarwasz review on #1680: expand the PoC bullet to make explicit that pushing a PoC to a public GitHub repo, gist, fork, or branch is public disclosure, and note that private repos require granting access to each PMC member individually. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|



No description provided.