The project takes security seriously and values responsible disclosure. This policy explains how to report a security issue and what to expect in response.
Please report security issues privately via the GitHub Security Advisory "Report a Vulnerability" tab. Do not file public issues or pull requests for security matters because public disclosure before a fix is in place puts users at risk.
Please provide:
- Reproduction steps, in point form.
- Affected components (e.g., specific prompts, code modules, configuration).
- Potential impact on confidentiality, integrity, and availability.
- Evidence from testing, including outputs from AI models, scanning tools, penetration testing tools, etc.
- Acknowledgment: Within 72 hours.
- Initial assessment: Within 7 days.
- Status updates: At least every 14 days until resolution.
The maintainers may request additional details to validate a report. Please respond promptly so we can keep the process moving.
In scope: Code, prompts, configuration, and documentation in this repository.
Out of scope:
- Third-party dependencies; please report directly to the respective maintainers.
- AI models referenced in prompts; please report directly to the model provider.
The project follows responsible disclosure. Reporters will be credited in the resolved advisory unless they request otherwise. This project does not offer monetary bounties.