Please report suspected vulnerabilities privately through the repository's GitHub Security Advisory page. Do not include API keys, access tokens, private prompts, chat records, proxy addresses, or generated user content in a public issue.
Include the affected Decuria version, Hermes Agent version, operating system, reproduction steps, and impact. Use synthetic credentials and data whenever possible.
If a credential may have appeared in a commit, log, screenshot, issue, chat, or other uncontrolled location, revoke or rotate it at the provider first. Removing it from the latest file is not sufficient because copies and Git history may remain.
Security fixes are applied to the latest released Decuria version. Users should upgrade both Decuria and Hermes Agent before reporting an issue already fixed upstream.