Skip to content

Security: BrokkAi/acp-go

Security

SECURITY.md

Security Policy

Report suspected vulnerabilities privately to feedback@brokk.ai. Include the affected version or commit, impact, and steps to reproduce. Remove credentials, personal data, and private repository contents from reports and logs.

Do not post vulnerabilities or working exploits in public issues. Use public issues for ordinary bugs; see CONTRIBUTING.md.

ACP agents and terminal commands run with the caller's operating-system permissions. The runner's path checks do not provide an OS sandbox.

There aren't any published security advisories