Security Policy
OpenClasp handles agent identity, authorization, agreements, and signed outcome records. Security reports are taken seriously.
Reporting a vulnerability
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository. If it is unavailable, open a public issue containing no vulnerability details and ask the maintainer to establish a private channel.
Include the affected component, impact, reproduction steps, and any suggested mitigation. Never include real credentials, private conversation content, or third-party personal data.
Scope
Security support applies to the latest release and the current main branch. OpenClasp is in beta;
there is no SLA, but confirmed reports will be acknowledged and prioritized.
Safe harbor
Good-faith research that avoids privacy violations, service disruption, persistence, and access to unrelated accounts is welcome. Stop testing and report immediately if you encounter sensitive data.