Skip to content

Security: ai-agent-assembly/agent-assembly

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x (alpha) ✅ Active development — security patches applied

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

To report a security issue, use GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click "Report a vulnerability".
  3. Fill in the details and submit.

Alternatively, email security@agent-assembly.dev with the subject line: [SECURITY] agent-assembly — <brief description>.

What to include

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a proof-of-concept.
  • The affected version(s) and component(s).
  • Any suggested mitigations, if known.

Response SLA

Stage Target
Initial acknowledgement Within 2 business days
Severity assessment Within 5 business days
Patch or mitigation Dependent on severity (Critical: 7 days, High: 14 days, Medium/Low: next release)

Disclosure Policy

We follow coordinated disclosure. Once a fix is available, we will:

  1. Release a patched version.
  2. Publish a GitHub Security Advisory.
  3. Credit the reporter (unless they prefer to remain anonymous).

There aren't any published security advisories