Skip to content

Security: sidman2/assetmason-agent-tools

Security

SECURITY.md

Security Policy

Supported versions

This project is in preview. The latest preview line receives best-effort security fixes.

Reporting a vulnerability

If GitHub private vulnerability reporting is enabled, use it.

If it is not enabled, open a minimal issue asking for a secure contact path. Do not include exploit details, secrets, tokens, private keys, or sensitive data in a public issue.

Scope

This policy covers the source code and npm packages in this repository.

Security posture

  • The tools are local-first developer utilities.
  • They do not send telemetry by default.
  • They must not capture credentials.
  • They must not require secrets for basic local usage.
  • Do not paste secrets into examples, issues, fixtures, or reports.
  • These tools are not a security audit, compliance audit, legal review, or certification product.

Response expectations

This is a preview, solo-maintained project. Security reports are handled on a best-effort basis and do not include a formal SLA.

There aren't any published security advisories