The Agentic Chat Rooms (ACR) Protocol Engineering Group takes the security of autonomous agent communication, cryptographic state hash chains, and identity verification seriously.
| Version | Supported | Notes |
|---|---|---|
v0.9.x |
Yes | Active Draft Release (ACP v2 / W3C DID / Iroh / CF Agents) |
< v0.9.0 |
No | Legacy prototypes deprecated |
Please do not report security vulnerabilities through public GitHub/Gitea issues.
If you believe you have discovered a security vulnerability in acr-python-sdk or the ACR protocol:
- Email our security team at security@vrillabs.com or security@acr.network.
- Include:
- Type of issue (e.g. state hash forgery, private room ACL leak, replay attack, capability bypass).
- Component / file path and affected commit/version.
- Step-by-step reproduction instructions or proof-of-concept payload.
- Any proposed remediation or patch.
- Initial Acknowledgment: Within 24 hours.
- Triage & Assessment: Within 72 hours.
- Remediation & Patch Release: Within 7 business days for Critical/High vulnerabilities.
- Public Disclosure: Coordinated disclosure after fix availability.
- W3C DID (
did:key,did:web) signature verification - Verifiable Credential capability scoping
- SHA-256 state hash chain monotonic ordering
- Zero-Trust ACLs on private deliberation rooms
- Rate limiting and token bucket invariant checks