Praxen is a security tool. We take vulnerabilities in Praxen itself seriously. This document describes how to report one privately, what is in scope, and what to expect after you report.
Praxen runs as a skill inside your coding agent (Claude Code, OpenAI Codex, or similar) — not as a standalone, sandboxed service. Two properties are worth stating plainly before you run it:
- Read-only by convention, not by isolation. Praxen is designed to operate read-only on the agent's workspace: it reads artifacts (code, config, logs, governance docs) and writes output only to its own
./reports/directory. It does not act on the agent's behalf and does not modify the agent's code, skill files, configuration, or dependencies. But this is a behavioral contract of the skill's instructions, not a technical sandbox — Praxen runs with the coding agent's ordinary tool access (including Bash and Write), so the read-only posture is enforced by convention rather than by an isolation boundary. (This is the same declared-versus-enforced distinction Praxen itself flags when it scans other agents.) Run Praxen only where you already trust the coding agent to operate. - Local by default. Reports are written locally to
./reports/(HTML, JSON, text). Nothing phones home.
For guidance on interpreting Praxen's output — a model-assisted expert review rather than a deterministic gate — see Working with Praxen.
In scope — vulnerabilities in Praxen itself:
- The
behavior-verifierskill (the prompt and step graph inskills/behavior-verifier/SKILL.md). - The deterministic renderer (
skills/behavior-verifier/render.py) and report template (report_template.html). - The findings-JSON schema validator (
skills/behavior-verifier/schema.py,findings.schema.json). - The plugin manifest (
.claude-plugin/plugin.json,marketplace.json). - The build (
build.sh) and release (.github/workflows/release.yml) pipelines, and the publishedpraxen-X.Y.Z.zipartifacts.
Examples of in-scope issues: an injection in a finding's evidence.snippet that escapes the HTML escaper and executes script in the rendered report; a path-traversal in render.py that lets a crafted findings JSON write outside the output directory; a tampered release artifact.
Out of scope — findings about the agents Praxen analyses. If you run Praxen against an AI agent and Praxen reports a finding against that agent, that is normal output of the tool, not a vulnerability in Praxen. Please report those to the agent's own maintainer, not here.
Do not file a public GitHub issue for a security vulnerability. Public issues are indexed and broadcast immediately; that is the wrong channel for an unpatched defect.
Use GitHub's private security advisory:
- Go to the Security tab on this repository.
- Click Report a vulnerability.
- Fill in the form. Include enough detail to reproduce — a minimal Praxen input, the observed output, and what you expected to differ. Attach the crafted findings JSON, remit, or repro script if applicable.
GitHub will create a private advisory thread between you and the project maintainers. We will respond there.
If GitHub Security Advisories are unavailable to you for any reason, email developer@exabeam.com with the subject line Praxen security report and the same level of detail.
- Initial acknowledgement: within 3 business days of your report.
- First substantive reply (we understand the issue, we agree on scope and severity, here is the plan): within 10 business days.
- Fix timeline: depends on severity and complexity. Critical issues are prioritised; expect a fix in an immediate patch release, rather than waiting for the next scheduled minor release.
- Coordinated disclosure: we prefer to ship the fix in a tagged release, publish a GitHub Security Advisory (with credit to you unless you ask otherwise), and request a CVE if the issue warrants one. We will coordinate the public-disclosure timing with you.
If you do not hear back from us within the windows above, please nudge the thread or escalate via the email address above.
Security fixes ship in the latest released 1.x line. There is no LTS branch and no back-porting to earlier minors; please upgrade to the latest tagged release before reporting.
| Version | Receiving security fixes |
|---|---|
| Latest tagged release | ✓ Yes — always upgrade to the newest release before reporting |
| Anything older than the latest release | No — no back-porting to earlier minors; no LTS branch |
0.x (pre-1.0) |
No — superseded, not maintained |
0.6.x and earlier (under the former name Praxa, at Exabeam/deckard) |
No — superseded by the rename, not maintained |