Skip to content

Security: agent-grounds/ephor

SECURITY.md

Security

Reporting a vulnerability

Report it privately, through GitHub: on the affected repository, open the Security tab and choose Report a vulnerability. Private vulnerability reporting is turned on for every public repository in this organization, and a report made that way is visible only to the maintainers until it is published.

Please do not open a public issue for a vulnerability. Issues here are read and worked by automation, in public, and an agent would set about reproducing it.

A report is most useful when it carries what any report here carries: the command, the directory, and the version or commit, what happened, and what should have happened instead — plus what an attacker gains.

What counts

These are developer tools that run on your machine, against your repositories, with your credentials. Of particular interest:

  • a repository's content — a plan, a template, a configuration file, a citation — causing a tool to run a command, or to write outside the places it says it writes;
  • a tool sending a credential, a token, or site-specific data somewhere its documentation does not say it goes;
  • a gate (grund check, fissile check) that can be made to pass over a tree it did not read.

A tool doing what its documentation says, run on a repository you chose to trust, is not a vulnerability: rhei runs the programs a plan names, and ephor runs the actions its configuration names. That is what they are for.

Supported versions

The latest release of each tool. Fixes are not backported.

There aren't any published security advisories