Skip to content

Security: colinagent/OpAgent

Security

SECURITY.md

Security Policy

Do not open public issues for suspected vulnerabilities. Report them privately through GitHub's security-advisory interface for colinagent/opagent and include affected versions, reproduction steps, impact, and any proposed fix.

Only the latest tagged release receives security fixes. The Runtime treats permissions and sandbox setup as fail-closed boundaries; reports showing a bypass of those boundaries are especially valuable.

There aren't any published security advisories