Skip to content

Security: 0YHR0/AgentMesh

Security

SECURITY.md

Security Policy

AgentMesh is currently in the design phase and has no production-ready release.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue. Use GitHub's private vulnerability reporting feature when it is enabled for this repository. Until then, contact the repository owner privately through their GitHub profile.

Security posture

The design assumes that agents, models, tools, MCP servers, A2A peers and retrieved content are not inherently trustworthy. The platform will apply least privilege, explicit authorization, audit logging, secret isolation, input validation, output validation and human approval for high-risk actions.

No current document should be interpreted as a production security guarantee.

There aren't any published security advisories