If you discover a security vulnerability in agent-privacy, please do not open a public issue. Instead, report it privately using GitHub's security advisory system:
Report a Security Vulnerability
When reporting, please include:
- A description of the vulnerability
- Steps to reproduce (if applicable)
- Potential impact
- Any proposed fixes or mitigations
We take all security reports seriously and will investigate promptly.
Agent-privacy is itself a security tool designed to detect and filter sensitive information (PII, credentials, injection attacks, and other risks) in AI agent interactions. Because of this critical security role, we treat vulnerabilities in the detection pipeline with the highest priority:
- High-priority issues: False negatives in PII/credential/injection detection; bypass techniques; unhandled attack vectors
- Medium-priority issues: Performance or stability issues; false positives that degrade usability
- Lower-priority issues: Documentation or non-security improvements
We aim to:
- Acknowledge your report within 48 hours
- Provide an initial assessment and update within 7 days
- Work with you toward a fix and coordinated disclosure timeline
Response times may vary based on complexity and severity.
Only the latest release is supported with security updates. We recommend always running the current version to ensure you have the latest PII detection rules and security fixes.
| Version | Supported |
|---|---|
| Latest | ✅ Yes |
| Older | ❌ No |
We follow coordinated disclosure practices:
- You report the vulnerability privately through GitHub security advisories
- We investigate and prepare a fix
- Once a patch is available, we coordinate with you on a disclosure timeline
- We release the fix and publicly acknowledge the issue (with your consent and attribution)
- We notify users through release notes and security advisories
This approach allows users time to update before the vulnerability is widely disclosed.
When using agent-privacy:
- Keep the tool updated to the latest version
- Review detection rules and patterns for your specific use case
- Monitor for false negatives in your environment
- Report any patterns that should be detected but are missed
Thank you for helping keep agent-privacy and the broader AI agent ecosystem secure.