Skip to content

Security: compuficial/agentfactory

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities privately via GitHub security advisories rather than opening a public issue. You'll get an acknowledgment within a few days.

Scope notes

af is a local-first tool: it manages processes you launch, on your machine, with your privileges. Reports we consider in scope include command injection through harness templates or config, sessions escaping their dedicated tmux socket, and secrets leaking into logs or --json output (session environments are deliberately excluded from the JSON schema — a leak there is a bug).

There aren't any published security advisories