From ddf2b5ef4e17a406ed84a0d8de98a46285df9674 Mon Sep 17 00:00:00 2001 From: thereisnotime <37583483+thereisnotime@users.noreply.github.com> Date: Tue, 4 Aug 2026 01:49:29 +0300 Subject: [PATCH 1/2] docs: add a security policy The issue template already routes security reports to security/advisories/new, but there is no SECURITY.md, so GitHub shows the repo as having no policy and the reporting route is undocumented everywhere else. Covers where to report, what to include, response and disclosure timelines, and what is in and out of scope. Adds two notes for self-hosters: a workspace token is one shared credential with no per-agent identity, and the identity provider settings decide which tenant a deployment trusts. Note the private reporting form linked from the issue template is currently disabled, so external reports get HTTP 403 'Repository does not have private vulnerability reporting enabled'. Enabling it in Settings > Code security would make that route work; the policy lists email as a fallback in the meantime. --- SECURITY.md | 61 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..494449d3f --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,61 @@ +# Security Policy + +## Reporting a Vulnerability + +Please report security issues privately, not in public issues, pull requests or +Discussions. + +Use GitHub's [private vulnerability +reporting](https://github.com/openagents-org/openagents/security/advisories/new). +If that page is unavailable, email **team@openagents.org** with `SECURITY` in +the subject. + +Please include: + +- what the issue is and which component it affects (network, workspace backend, + workspace frontend, launcher, SDK) +- the version, tag or commit you tested against +- steps to reproduce, ideally the smallest set that shows the problem +- what an attacker gains, and what they need first (a workspace token, a + workspace id, an account somewhere else) + +You will get an acknowledgement within 5 working days. Please give us 90 days +before public disclosure, or less if a fix ships sooner. + +## Scope + +In scope: + +- the network and its transports (HTTP, gRPC, MCP, A2A) +- the workspace backend and frontend +- the launcher and agent adapters +- the published container image and npm packages + +Out of scope: + +- vulnerabilities in an agent runtime the launcher shells out to (Claude Code, + Codex, Cursor and so on). Report those to their maintainers. +- anything requiring a workspace token you were already given. The token is the + credential for a workspace. +- findings against `workspace.openagents.org` that only affect your own + workspace. + +## Notes for self-hosted deployments + +Two properties of the current design are worth stating plainly, because they +shape what does and does not count as a vulnerability. + +**A workspace token is a single shared credential.** Every agent in a workspace +sends the same `X-Workspace-Token`, and `agent_name` is self-declared. There is +no per-agent identity and revocation is all or nothing. Use one workspace per +trust boundary rather than one workspace for everything. + +**Identity providers must be configured explicitly.** `FIREBASE_PROJECT_ID` and +`APPLE_CLIENT_IDS` control which identity tenant this deployment trusts. Setting +them to a tenant you do not operate means accepting logins minted there. Leave +them empty unless you own the tenant. + +## Supported Versions + +Fixes land on `develop` and ship in the next release. Only the latest release is +supported; there are no backports to older tags. From 3b6e04308c5a9ca61dd9480afc38b331beecec35 Mon Sep 17 00:00:00 2001 From: Nebu Kaga Date: Tue, 29 Sep 2026 23:36:39 +0000 Subject: [PATCH 2/2] docs(security): keep the policy to this project Name no third-party products: the out-of-scope agent runtimes and the transport protocols are described generically, and the identity-provider note no longer lists specific vendor variables. Drop the container image from scope (it and its publish workflow were removed this month) and the self-declared agent_name detail, which is an implementation note rather than policy. --- SECURITY.md | 37 ++++++++++++++++++------------------- 1 file changed, 18 insertions(+), 19 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 494449d3f..b0dc73743 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -5,10 +5,10 @@ Please report security issues privately, not in public issues, pull requests or Discussions. -Use GitHub's [private vulnerability -reporting](https://github.com/openagents-org/openagents/security/advisories/new). -If that page is unavailable, email **team@openagents.org** with `SECURITY` in -the subject. +Use the repository's [private vulnerability +reporting](https://github.com/openagents-org/openagents/security/advisories/new) +form. If that page is unavailable, email **team@openagents.org** with `SECURITY` +in the subject. Please include: @@ -26,15 +26,15 @@ before public disclosure, or less if a fix ships sooner. In scope: -- the network and its transports (HTTP, gRPC, MCP, A2A) +- the network and its transports - the workspace backend and frontend -- the launcher and agent adapters -- the published container image and npm packages +- the launcher and its agent adapters +- the published npm packages Out of scope: -- vulnerabilities in an agent runtime the launcher shells out to (Claude Code, - Codex, Cursor and so on). Report those to their maintainers. +- vulnerabilities in a third-party agent runtime the launcher shells out to. + Report those to that project's maintainers. - anything requiring a workspace token you were already given. The token is the credential for a workspace. - findings against `workspace.openagents.org` that only affect your own @@ -42,18 +42,17 @@ Out of scope: ## Notes for self-hosted deployments -Two properties of the current design are worth stating plainly, because they -shape what does and does not count as a vulnerability. +Two properties of the current design shape what does and does not count as a +vulnerability. **A workspace token is a single shared credential.** Every agent in a workspace -sends the same `X-Workspace-Token`, and `agent_name` is self-declared. There is -no per-agent identity and revocation is all or nothing. Use one workspace per -trust boundary rather than one workspace for everything. - -**Identity providers must be configured explicitly.** `FIREBASE_PROJECT_ID` and -`APPLE_CLIENT_IDS` control which identity tenant this deployment trusts. Setting -them to a tenant you do not operate means accepting logins minted there. Leave -them empty unless you own the tenant. +authenticates with the same token, and revocation is per workspace. Use one +workspace per trust boundary rather than one workspace for everything. + +**Identity providers must be configured explicitly.** The identity-provider +settings name the tenant a deployment trusts. Pointing them at a tenant you do +not operate means accepting logins minted there. Leave them empty unless you +own the tenant. ## Supported Versions