Skip to content

Security: sageox/agent-toolkit

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities privately — do not open a public issue. Public issues disclose the problem before a fix is available.

Use GitHub Security Advisories: on this repository's Security tab, click Report a vulnerability. If you can't use that, email security@sageox.ai.

Please include:

  • Affected revision — a release or commit SHA.
  • Reproduction — the smallest steps or proof of concept that triggers it.
  • Impact — what an attacker could do.

Agents may handle chat content, API tokens, signing keys, and tool results. Never paste real customer data, messages, credentials, private keys, or access tokens into a report; use synthetic data to demonstrate the issue.

Response

We'll acknowledge your report, investigate, and work on a fix. We practice coordinated disclosure: we'll agree on a disclosure timeline with you and credit you when the fix ships, unless you'd prefer to stay anonymous.

Supported versions

The SageOx Agent Toolkit is pre-release. Until versioned releases begin, security fixes are made only on the latest revision of main.

Version Supported
Latest main
Older revisions

There aren't any published security advisories