Skip to content

Security: arcacomputer/headlong-agent-findings

SECURITY.md

Security Policy

Reporting a sensitive disclosure

Do not open a public issue containing credentials, personal information, raw agent trajectories, private filesystem paths, or unredacted experiment data.

Use GitHub's private vulnerability reporting feature for this repository. If that feature is unavailable, contact the repository maintainers privately before sharing evidence.

Published-data policy

This repository intentionally excludes:

  • API keys, access tokens, cookies, and environment files;
  • raw chats, raw trajectories, and identity exports;
  • personal names, email addresses, usernames, and hostnames;
  • container identifiers, process identifiers, and private network details;
  • generated authentication tokens and repository contents from the experiment.

If sensitive material is discovered, preserve the evidence privately, remove it from the public Git history, rotate affected credentials, and document only the sanitized remediation.

There aren't any published security advisories