We take the security of the AgentKit product family seriously — the ak CLI, AgentKit Desktop App, Engineer Kit, and Marketing Kit.
Please do not report security vulnerabilities through public GitHub issues or discussions.
Instead, report them privately through one of these channels:
-
GitHub Private Vulnerability Reporting (preferred) — use the Report a vulnerability button under this repository's Security tab. This opens a private advisory visible only to you and the maintainers.
-
Email — if you cannot use GitHub, contact the maintainers privately (see the AgentKit website for the current security contact).
To help us triage quickly, please include:
- The affected product and version.
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a proof of concept.
- Any suggested mitigation, if known.
Please redact secrets, tokens, credentials, and personal data from anything you share.
- We will acknowledge your report as soon as possible.
- We will keep you informed as we investigate and work on a fix.
- We will credit you for the discovery once a fix is released, unless you prefer to remain anonymous.
Thank you for helping keep AgentKit and its users safe.