Report a security issue
Send suspected vulnerabilities through a private channel, rather than a public issue, discussion, or pull request. This gives the maintainers time to investigate and coordinate a fix.
Choose a reporting channel
Section titled “Choose a reporting channel”| Affected component | Private reporting channel |
|---|---|
| CLI | Report a vulnerability on GitHub |
| Android app | Report a vulnerability on GitHub |
| Agent skill, plugins, or marketplaces | security@fulldisclosure.fi |
| Relay, website, protocol, several components, or an uncertain component | security@fulldisclosure.fi |
Full Disclosure operates Agentknock and receives reports at that address. Send one email for an issue affecting several components. Email is also available if you cannot use the GitHub reporting route.
Describe the problem
Section titled “Describe the problem”Include what you have available:
- The affected component, version, and operating system.
- For the skill or plugins, the Git commit or the date you obtained that copy when known, plus the agent host, model, execution environment, and how you loaded the skill.
- The security impact and conditions needed to trigger it.
- Steps to reproduce it, with a small proof of concept or relevant logs.
- A possible mitigation or fix, if you have identified one.
Only the latest CLI and Android releases receive security fixes. Check whether the issue affects the latest release of the component you are reporting.
Skill and plugin security fixes are published on master. Check whether the issue also affects the current revision.
Use test credentials and remove live credentials, pairing data, and personal data from logs and screenshots. Test only systems you own or have permission to test. If you encounter another person’s data, stop testing and report the issue.
The CLI security policy, Android security policy, and skill and plugin security policy describe testing and coordinated disclosure. The maintainers will coordinate disclosure and credit with you; you can ask to remain anonymous.