Please do not open public GitHub issues for suspected security vulnerabilities.
Instead, use one of the following private channels:
- Preferred: Open a private GitHub Security Advisory on this repository.
- Alternative: Email the AFI Core Maintainers via the address
listed at
.well-known/security.txt.
Full policy: see Community → Security.
- Acknowledgment: within 5 business days
- Triage: within 14 days
- Coordinated disclosure: typically 60–90 days for spec bugs, 30–60 for implementation bugs
- ✅ In scope: the AFI specification, reference libraries maintained in this org, the conformance test kit
- ❌ Out of scope: vulnerabilities in specific providers (contact the provider directly), third-party agent runtimes that integrate AFI