Skip to content

Security: ondrakingboss/agent-ops

SECURITY.md

Security Policy

Supported version

Security fixes are applied to the latest release on main.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting feature for this repository. Do not open a public issue containing credentials, exploit details, private prompts, provider evidence, or personal data.

If private reporting is unavailable, open a minimal issue requesting a private contact channel without including sensitive details.

Security boundary

  • Provider and benchmark-executor profiles ship disabled and dry-run-only.
  • Real provider execution requires explicit configuration, credentials, approval, allowlisted role/model/endpoint, limits, and --execute.
  • Agent Ops stores local integrity hashes; they detect changes but are not remote signatures or provider billing verification.
  • Mutable approvals, attempts, checkpoints, receipts, evidence, reports, and logs are local operational records and may contain sensitive metadata.
  • Never commit API keys, .env files, raw prompts, or unreviewed operational evidence.

Installation or tests do not make model-provider calls. Optional live tests are gated by AGENTOPS_LIVE_PROVIDER_TEST=1 and separate credentials.

There aren't any published security advisories