Skip to content

Security: SLYysl/agent-road

SECURITY.md

Security

Agent Road can execute administrative commands on enrolled computers. Use it only on devices whose owners authorized access. Never share controller state, SSH keys, API credentials or live pairing commands.

This is an experimental Alpha. No supported stable version or security response SLA is declared.

Report vulnerabilities through GitHub private vulnerability reporting, or privately to syin31437@gmail.com with subject Agent Road security report. GitHub private reporting is enabled. Start with a minimal redacted description; do not send credentials or raw device logs. Do not report vulnerabilities in public issues.

Reports should identify the affected revision, expected permission boundary, minimal redacted reproduction and observed impact. Do not test against other users or the hosted production service without explicit permission.

There aren't any published security advisories