Skip to content

Security: JackDDavis/agent-privacy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in agent-privacy, please do not open a public issue. Instead, report it privately using GitHub's security advisory system:

Report a Security Vulnerability

When reporting, please include:

  • A description of the vulnerability
  • Steps to reproduce (if applicable)
  • Potential impact
  • Any proposed fixes or mitigations

We take all security reports seriously and will investigate promptly.

Scope

Agent-privacy is itself a security tool designed to detect and filter sensitive information (PII, credentials, injection attacks, and other risks) in AI agent interactions. Because of this critical security role, we treat vulnerabilities in the detection pipeline with the highest priority:

  • High-priority issues: False negatives in PII/credential/injection detection; bypass techniques; unhandled attack vectors
  • Medium-priority issues: Performance or stability issues; false positives that degrade usability
  • Lower-priority issues: Documentation or non-security improvements

Response Timeline

We aim to:

  • Acknowledge your report within 48 hours
  • Provide an initial assessment and update within 7 days
  • Work with you toward a fix and coordinated disclosure timeline

Response times may vary based on complexity and severity.

Supported Versions

Only the latest release is supported with security updates. We recommend always running the current version to ensure you have the latest PII detection rules and security fixes.

Version Supported
Latest ✅ Yes
Older ❌ No

Disclosure Policy

We follow coordinated disclosure practices:

  1. You report the vulnerability privately through GitHub security advisories
  2. We investigate and prepare a fix
  3. Once a patch is available, we coordinate with you on a disclosure timeline
  4. We release the fix and publicly acknowledge the issue (with your consent and attribution)
  5. We notify users through release notes and security advisories

This approach allows users time to update before the vulnerability is widely disclosed.

Security Best Practices

When using agent-privacy:

  • Keep the tool updated to the latest version
  • Review detection rules and patterns for your specific use case
  • Monitor for false negatives in your environment
  • Report any patterns that should be detected but are missed

Thank you for helping keep agent-privacy and the broader AI agent ecosystem secure.

There aren't any published security advisories