Skip to content

Report a security issue

Send suspected vulnerabilities through a private channel, rather than a public issue, discussion, or pull request. This gives the maintainers time to investigate and coordinate a fix.

Affected component Private reporting channel
CLI Report a vulnerability on GitHub
Android app Report a vulnerability on GitHub
Agent skill, plugins, or marketplaces security@fulldisclosure.fi
Relay, website, protocol, several components, or an uncertain component security@fulldisclosure.fi

Full Disclosure operates Agentknock and receives reports at that address. Send one email for an issue affecting several components. Email is also available if you cannot use the GitHub reporting route.

Include what you have available:

  • The affected component, version, and operating system.
  • For the skill or plugins, the Git commit or the date you obtained that copy when known, plus the agent host, model, execution environment, and how you loaded the skill.
  • The security impact and conditions needed to trigger it.
  • Steps to reproduce it, with a small proof of concept or relevant logs.
  • A possible mitigation or fix, if you have identified one.

Only the latest CLI and Android releases receive security fixes. Check whether the issue affects the latest release of the component you are reporting.

Skill and plugin security fixes are published on master. Check whether the issue also affects the current revision.

Use test credentials and remove live credentials, pairing data, and personal data from logs and screenshots. Test only systems you own or have permission to test. If you encounter another person’s data, stop testing and report the issue.

The CLI security policy, Android security policy, and skill and plugin security policy describe testing and coordinated disclosure. The maintainers will coordinate disclosure and credit with you; you can ask to remain anonymous.