Skip to content

Security: HadjievK/AgentRecovery

Security

SECURITY.md

Security Policy

Agent Recovery is currently a specification draft and reference material, not a production recovery controller.

Do not place credentials, private business data, or executable secrets in a RECOVERY.yaml, RECOVERY.md, or public issue. Recovery machines are security-sensitive supply-chain artifacts and must not be treated as authorization grants.

For a suspected vulnerability, use GitHub's private vulnerability reporting when available. If it is not available, contact the repository owner privately rather than opening a public issue with exploit details.

Security fixes target the latest revision of the draft. No stable-version support policy exists before 1.0.

There aren't any published security advisories