Found a security hole? Impressive. Most impressive.
DO NOT open a public issue. We don't need the Rebel Alliance knowing our weaknesses.
Email the maintainer or use GitHub's private vulnerability reporting.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
- Prompt injection that breaks containment
- Anything that leaks system prompts or internal state
- Exploits that allow unintended system access
- Ways to make the agent do Actually Bad Things™
- "The agent gave me Machiavellian advice" — that's the feature, not a bug
- "This could be used for evil" — see above
- "The ethics are questionable" — you're holding a tool called PALPATINE
- Acknowledgment: 48 hours
- Initial assessment: 1 week
- Fix (if applicable): Depends on severity
| Version | Supported |
|---|---|
| Latest | ✓ |
| Older | No |
We don't backport. Update your installation. The Empire waits for no one.
There are none. This is a side project, not a corporation. Your reward is:
- Credit in the changelog
- Our eternal gratitude
- The satisfaction of having helped
"Your overconfidence is your weakness." — Luke Skywalker "Your faith in your friends is yours." — Palpatine
Don't let overconfidence in security be ours. Report responsibly.