Skip to content

Security: DesusLove/VibeTrading

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security issues to desuslove@users.noreply.github.com.

Do not open public GitHub issues for security vulnerabilities.

Scope

  • API authentication bypass
  • Remote code execution in agent tools
  • Credential leakage via logs or error messages
  • Prompt injection enabling unauthorized actions

Out of Scope

  • LLM prompt injection that a human operator could also be tricked by
  • Theoretical attacks requiring physical access

Disclosure

We aim to acknowledge receipt within 48 hours and provide a fix timeline within 5 business days.

There aren't any published security advisories