Skip to content

Security: haochencheng/Agents-Memory

Security

SECURITY.md

Security Policy

Scope

Use this channel for security vulnerabilities, credential exposure, unsafe defaults, or other issues where public disclosure would create unnecessary risk.

Reporting

  1. Do not open a public GitHub issue for a suspected vulnerability.
  2. Contact the maintainers through a private GitHub security advisory or another private maintainer channel when available.
  3. Include affected command or workflow, reproduction steps, impact, and any temporary mitigation you have identified.

What To Include

  1. Repository version or commit reference.
  2. Affected files, commands, or bootstrap path.
  3. Clear reproduction steps.
  4. Expected impact and severity estimate.
  5. Whether the issue exposes secrets, private paths, or cross-project data.

Response Expectations

Maintainers will try to confirm the report, assess severity, and coordinate remediation before public disclosure. Response time is best effort and depends on maintainer availability.

Disclosure Guidance

Please avoid sharing exploit details publicly until maintainers have had a reasonable chance to assess and address the issue.

There aren't any published security advisories