Skip to content

Security: BaseLayerAI/agent-host-provisioning

SECURITY.md

Security Policy

Reporting a vulnerability

Use GitHub private vulnerability reporting: on the affected repo, go to Security → Report a vulnerability and open a private advisory. Do not open a public issue for anything exploitable.

You can expect an acknowledgment within a few days. These are personally-operated agents, not commercial products — there is no bug bounty, but reports are read and acted on.

If you find a leaked credential

These agents hold API keys, bot tokens, and session cookies, so a leak is the most likely real incident. If you spot one in a commit, log, issue, or artifact:

  1. Assume it is live and act as if it is being exploited. Do not test it.
  2. Report it immediately via a private advisory on the affected repo, with the file/commit reference. The operator will rotate first, then investigate — rotation is never blocked on figuring out how the leak happened.
  3. Do not share, cache, or repost the credential anywhere else, including in the advisory title (titles can become public).

Scope

All repos under the BaseLayerAI org. Vulnerabilities in upstream dependencies should be reported upstream; a note here is still welcome if an agent's usage makes it exploitable.

There aren't any published security advisories