Skip to content

Security: sust4in/agentproof

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in agentproof, please report it through GitHub's private vulnerability reporting.

Do not open a public issue for security vulnerabilities.

Scope

agentproof executes user-defined verifiers which may run subprocesses (shell commands, scanners, compilers). The SDK does not sandbox these executions. Users are responsible for ensuring verifiers run trusted commands in trusted environments.

Supported versions

Only the latest release receives security updates.

There aren't any published security advisories