If you discover a security vulnerability in Agent Passport:
- Do not open a public GitHub issue with exploit details.
- Instead, email the maintainer directly (or use GitHub Security Advisories if enabled).
- Please include:
- A description of the vulnerability
- Steps to reproduce
- Any potential impact you see
- Suggested remediation, if you have one
We will:
- Acknowledge receipt as quickly as possible.
- Investigate and, if confirmed, work on a fix.
- Coordinate a responsible disclosure timeline where appropriate.
Agent Passport is designed to mitigate:
- Malicious Passports: schema/semantic validation and permission policies.
- Malicious tools: virtualized tools for destructive operations in tests.
- Prompt injection attempts: behavior contracts + tool/permission enforcement.
- Sandbox escape attempts: Docker sandbox executor (non-root, resource limits, no host Docker socket).
- Secret exfiltration: redaction in traces, deny-by-default network policies for some runtimes.
- Forged evidence: SHA-256 hashes and Ed25519 signatures on evidence bundles.
- It does not magically make untrusted LLM providers safe.
- It does not prevent model-level jailbreaks; it detects violations when observable via behavior contracts and traces.
- It does not provide full multi-tenant isolation; treat the stack as a component within your broader secured environment.
- Run sandboxed execution workers in restricted environments (e.g. separate node pool, locked-down network).
- Use separate credentials per runtime adapter, scoped with least privilege.
- Always scan container images and dependencies in CI.