Skip to content

Security: BADMAN4LIFE/LocalAgent

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open public issues for security-sensitive reports.

Instead, contact:

Include:

  • Affected version/commit
  • Reproduction steps
  • Impact assessment
  • Suggested mitigation (if known)

Response Expectations

  • Initial acknowledgement target: within 72 hours
  • Triage + severity classification: as quickly as possible
  • Patch timeline depends on severity and exploitability

Scope

Security reports are most helpful when they relate to:

  • Trust/approval bypass
  • Tool execution gate bypass
  • Policy enforcement bypass
  • Sensitive data leakage from artifacts/events/logs
  • Unsafe defaults regression

There aren’t any published security advisories