Skip to content

Security: jeremylongworth-source/AgentManufacturing

SECURITY.md

Security policy

No supported public release or response-time commitment has been established. Repository validation and the AM-30/31 assisted evaluations do not certify safe model behavior. Manufacturing safeguards, engineering authority, data integrity and jurisdiction/source uncertainty remain explicit boundaries.

Reporting status

Use GitHub private vulnerability reporting to send a security report to this repository's maintainers. A GitHub account is required. Jeremy Longworth is the project owner responsible for triage.

GitHub private vulnerability reporting was enabled and confirmed through the repository API on 2026-09-12 at the owner's request. This verifies the setting, not report delivery or response time; no test report was submitted. This replaces the previously published personal email route for security reports.

Do not disclose exploitable details, personal information, plant records or credentials through public issues, pull requests or comments. Use the private reporting link above and minimize sensitive details to what is needed for review. Conduct concerns follow CODE_OF_CONDUCT.md; the vulnerability channel is for security reports.

Report contents

Include affected revision/package, a minimal synthetic reproduction, expected versus observed boundary behavior, impact and relevant tool/model context. Distinguish unsafe operational advice, source-instruction injection, record falsification and information disclosure. Do not test against production equipment, third-party systems or data without authorization.

Proposed handling process

Jeremy Longworth is the designated recipient. The review process is to triage privately, preserve reproduction evidence, agree any disclosure timing, and review the fix and regression checks before publication. No response deadline or service-level promise is made. This policy does not grant testing permission or legal safe harbour.

For an actual site hazard, use the site's established emergency/safety process and responsible personnel. A repository report is not an emergency response channel.

There aren't any published security advisories