Frontier shells out to harness CLIs and can optionally write to a workspace when a delegation uses --write. Security issues in this repo should be treated as runtime and credential-boundary issues, not only web vulnerabilities.
Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue for a vulnerability until there is a fix or mitigation.
If GitHub Security Advisories are not available, open a minimal issue asking for a private contact path without including exploit details.
High-priority issues include:
- leaking API keys, model provider tokens, or local credential file contents;
- bypassing the selected-provider guardrails and silently falling back to an unintended provider or model;
- command injection through slash-command arguments, backend config, model names, or job ids;
- unintended writes when a task did not request
--write; and - reading or persisting sensitive local files outside documented config paths.
Only the current main branch is supported until the project starts publishing tagged releases.