Skip to content

AGENTS.md: link the project's security model for agent discoverability#15706

Open
potiuk wants to merge 1 commit into
apache:8.0.xfrom
potiuk:asf-security/agents-md-security-link-2026-05-31
Open

AGENTS.md: link the project's security model for agent discoverability#15706
potiuk wants to merge 1 commit into
apache:8.0.xfrom
potiuk:asf-security/agents-md-security-link-2026-05-31

Conversation

@potiuk
Copy link
Copy Markdown
Member

@potiuk potiuk commented May 31, 2026

This is a proposal for the PMC to review — please correct, reject, or discuss as needed. Nothing here is a requirement; the maintainer is the decision-maker.

This adds a "Security model" pointer to the Reporting Vulnerabilities section of AGENTS.md so an automated scan agent can mechanically discover the project's security model via the conventional AGENTS.md → SECURITY.md → THREAT_MODEL.md chain. SECURITY.md and THREAT_MODEL.md already exist on this branch; AGENTS.md currently points only at the generic ASF Security Team page, so the chain doesn't start from there. This PR adds only that link — no model content changes.

Context: the ASF Security team is preparing the project for an automated agentic security scan we're piloting. Such scans refuse to run if the model isn't mechanically discoverable by that path (refusing upfront beats wasting reviewer cycles on a noise-heavy run against a model the agent never found). Discoverability is the one hard gate; everything else is suggestion.

Questions / pushback welcome — happy to move the line or adjust wording to match house style.

@testlens-app
Copy link
Copy Markdown

testlens-app Bot commented May 31, 2026

✅ All tests passed ✅

🏷️ Commit: d2b4b74
▶️ Tests: 40180 executed
⚪️ Checks: 35/35 completed


Learn more about TestLens at testlens.app.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant