The developers of Wolfclaw prioritize security and stability. Please ensure you are running the latest "Sovereign" build.
| Version | Supported |
|---|---|
| 2.0.x | ✅ |
| 1.x.x | ❌ |
Wolfclaw is a tool with high system-level access. We take security reports seriously.
If you discover a security vulnerability within Wolfclaw, please do not open a public issue. Instead, follow these steps:
- Draft a Detailed Report: Include the nature of the vulnerability, a proof-of-concept (if possible), and the potential impact.
- Submit via Secure Channel: Email the lead developer (Pravin A Mathew) at a secure address or use the project's encrypted gateway if available.
- Wait for Response: We aim to acknowledge reports within 48 hours and provide a timeline for a fix.
- Core LLM Routing logic.
- Session Management & Authenticaton.
- Workspace Isolation/Docker execution.
- Path sanitization.
- Third-party LLM provider vulnerabilities (OpenAI, Anthropic, etc.).
- Misconfiguration of local hardware/OS by the user.
We ask that you observe "Responsible Disclosure" practices—giving the development team reasonable time to address the issue before making it public.
Stay Sovereign. Stay Secure.