If you discover a security vulnerability in Tylluan, do not open a public issue.
Instead, report it via GitHub Private Vulnerability Reporting: https://github.com/forja-orca/tylluan/security/advisories/new
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 7 days for critical issues.
| Version | Supported |
|---|---|
| latest main | ✅ |
| older releases | Best effort |
For a detailed analysis of Tylluan's security posture, including its mapping against the OWASP Top 10 for Agentic Applications (2026), see docs/concepts/SECURITY.md.
Tylluan is experimental research software. Key security gaps are documented in DISCLAIMER.md. The most significant:
- No code execution sandbox (bash/code guilds run with user privileges)
- No per-agent access control (bearer token grants full access)
- No automatic kill switch for rogue agents