Please report suspected vulnerabilities privately — do not open a public issue. Public issues disclose the problem before a fix is available.
Use GitHub Security Advisories: on this repository's Security tab, click Report a vulnerability. If you can't use that, email security@sageox.ai.
Please include:
- Affected revision — a release or commit SHA.
- Reproduction — the smallest steps or proof of concept that triggers it.
- Impact — what an attacker could do.
Agents may handle chat content, API tokens, signing keys, and tool results. Never paste real customer data, messages, credentials, private keys, or access tokens into a report; use synthetic data to demonstrate the issue.
We'll acknowledge your report, investigate, and work on a fix. We practice coordinated disclosure: we'll agree on a disclosure timeline with you and credit you when the fix ships, unless you'd prefer to stay anonymous.
The SageOx Agent Toolkit is pre-release. Until versioned releases begin, security
fixes are made only on the latest revision of main.
| Version | Supported |
|---|---|
Latest main |
✅ |
| Older revisions | ❌ |