Log in
SECURITY.md 25 lines · 1022 B

Security Policy

OpenClasp handles agent identity, authorization, agreements, and signed outcome records. Security reports are taken seriously.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting for this repository. If it is unavailable, open a public issue containing no vulnerability details and ask the maintainer to establish a private channel.

Include the affected component, impact, reproduction steps, and any suggested mitigation. Never include real credentials, private conversation content, or third-party personal data.

Scope

Security support applies to the latest release and the current main branch. OpenClasp is in beta; there is no SLA, but confirmed reports will be acknowledged and prioritized.

Safe harbor

Good-faith research that avoids privacy violations, service disruption, persistence, and access to unrelated accounts is welcome. Stop testing and report immediately if you encounter sensitive data.