| Version | Supported |
|---|---|
| 0.1.x | ✅ |
We take security seriously. If you discover a security vulnerability in Agent Runtime, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, use the repository's private vulnerability reporting.
Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
We will acknowledge the report, assess its impact, and coordinate disclosure through the private advisory.
The following are in scope for security reports:
- Authentication and authorization bypasses
- Remote code execution vulnerabilities
- Token leakage or theft vectors
- Cross-origin security issues
- Privilege escalation
The following are out of scope:
- Denial of service (the runtime is designed for local use)
- Issues requiring physical access to the machine
- Issues in dependencies (please report to the upstream project)
- Social engineering attacks
We appreciate security researchers who help keep Agent Runtime secure. With your permission, we will acknowledge your contribution in our release notes.
When using Agent Runtime:
- Only pair trusted origins - The runtime executes arbitrary code on your behalf
- Review pairing requests carefully - Verify the origin before approving
- Revoke unused pairings - Use
agent-runtime pairing listand revoke old entries - Keep the runtime updated - Install security updates promptly
- Use separate labs for sensitive work - Isolate different projects
See docs/security.md for the full security model.