Please report suspected vulnerabilities privately through GitHub Security Advisories:
https://github.com/agent-layer-mcp/agent-layer-core/security/advisories/new
Do not include secrets, personal records, production tokens, or exploit details in a public issue. Include the affected function or wire format, a minimal reproduction, expected impact, and any proposed mitigation you have already considered.
We will acknowledge a valid private report, investigate it, and coordinate disclosure before publishing details. We do not currently offer a bug bounty or promise a fixed response SLA.
Security fixes target the latest tagged release and main. This project is pre-1.0; consumers should pin exact versions and review release notes before upgrading.
This policy covers code in this repository. Agent Layer's hosted-service and product-security reports should use the private support channel shown in the relevant product.