Do not open a public GitHub issue for security reports.
Send a private report to security@kontourai.com with:
- a short summary of the issue
- affected versions or commit range
- reproduction steps or proof of concept
- impact assessment
- any suggested remediation
If email is not possible, open a private GitHub security advisory draft instead.
- We will acknowledge receipt within 3 business days.
- We will aim to confirm impact and next steps within 7 business days.
- We will coordinate on disclosure timing once a fix exists or a mitigation is available.
Security issues in scope include:
- command execution or injection flaws
- privilege or permission escalation
- unsafe handling of secrets or credentials
- artifact or workflow trust-boundary violations
- supply-chain or package-publishing exposure in this repository
Quality bugs, documentation bugs, and feature requests should go through the normal issue tracker.