Skip to content

Security: zetaaztra/wolfclaw

Security

SECURITY.md

Security Policy

Supported Versions

The developers of Wolfclaw prioritize security and stability. Please ensure you are running the latest "Sovereign" build.

Version Supported
2.0.x
1.x.x

Reporting a Vulnerability

Wolfclaw is a tool with high system-level access. We take security reports seriously.

If you discover a security vulnerability within Wolfclaw, please do not open a public issue. Instead, follow these steps:

  1. Draft a Detailed Report: Include the nature of the vulnerability, a proof-of-concept (if possible), and the potential impact.
  2. Submit via Secure Channel: Email the lead developer (Pravin A Mathew) at a secure address or use the project's encrypted gateway if available.
  3. Wait for Response: We aim to acknowledge reports within 48 hours and provide a timeline for a fix.

Scope

  • Core LLM Routing logic.
  • Session Management & Authenticaton.
  • Workspace Isolation/Docker execution.
  • Path sanitization.

Out of Scope

  • Third-party LLM provider vulnerabilities (OpenAI, Anthropic, etc.).
  • Misconfiguration of local hardware/OS by the user.

Responsible Disclosure

We ask that you observe "Responsible Disclosure" practices—giving the development team reasonable time to address the issue before making it public.


Stay Sovereign. Stay Secure.

There aren't any published security advisories