Skip to content

Security: kiyeonjeon21/trusted-agent-stack

SECURITY.md

Security policy

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting flow:

https://github.com/kiyeonjeon21/trusted-agent-stack/security/advisories/new

Include:

  • the affected commit or version;
  • reproduction steps;
  • expected and observed behavior;
  • security impact;
  • a minimal proof of concept without real credentials or customer data.

You should receive an acknowledgement within seven days. Public disclosure should wait until a fix or mitigation is available.

Scope

Especially relevant reports include:

  • prompt-injection bypasses;
  • fail-open verification behavior;
  • unsafe tool execution;
  • cache poisoning or receipt tampering;
  • credential exposure;
  • path traversal or arbitrary file access;
  • MCP tool-boundary violations.

The invoice payment flow is intentionally simulated and is not a production payment system. Reports that require connecting it to a real financial system are out of scope.

Supported versions

Until the first stable release, only the latest commit on main receives security updates.

There aren't any published security advisories