Governance
PickBits maintains ACVE, its schemas, CLI, and public registry. There is currently one maintainer, who is responsible for releases, repository permissions, and the final status of advisories. Until a second maintainer joins, changes are merged by that maintainer after CI passes; the merge history shows this.
Editorial policy
ACVE records the configuration in which an AI agent, pursuing a goal, did harm: the harness, model, goal, tools and approval involved, what the agent could reach, and how pursuing the goal turned into harm. These behaviour records are the registry's main list.
Product defects and malicious packages that put agents at risk are kept as related flaw records. A defect that has a CVE and needs no agent misbehaviour is already covered by CVE and OSV; when ACVE deliberately leaves one out, it is listed in advisories/EXCLUDED.json with the reason.
Sources:
- Each exposure axis cites its own source and says whether it is confirmed, detected or unconfirmed.
- First-hand accounts come first: the operator's own post, issue or transcript, the vendor's report, the researcher's write-up. News coverage is a reference, not a primary.
- A goal is recorded only as the source states it. When the source does not state one, the record says "Any …" and marks it unstated.
- A record says whether anyone reproduced the behaviour. Most records are recorded from sources and not recreated in a lab, and the record page says so.
Records are drafted with AI coding agents, including Claude Code and Codex, and reviewed by the maintainer before they are published. The same evidence rules apply to every vendor, including the makers of those agents.
Conflicts of interest
PickBits builds its own software with AI coding agents, including Claude Code and Codex, and pays for them as a customer. PickBits has no investment in, partnership with, or sponsorship from any vendor named in the registry. The registry names products from those vendors and their competitors. To keep that from shaping the records:
- Every vendor is held to the same publication rules in spec/advisory.md; no vendor's record is published, held back or softened on any other basis.
- A record about a product PickBits uses, sells or competes with says so in its details.
- The maintainer declares any new commercial relationship with a named vendor in this file before merging records about that vendor.
Notice and right of reply
Records are built from public sources and go live after review; the named parties are not notified in advance. When a record names a product's maker, or a party that controls the harm such as an infrastructure provider, the maintainer sends that party's published security or press contact a link to the record when it goes live.
The party may reply at any time. A public reply is recorded in occurrence.responses with its status (acknowledged, fixed or disputed) and a link. A reply sent privately is quoted in the record only with the sender's permission. A reply that shows a fact is wrong, with a source, is corrected in the record; the record's modified date changes and the correction is noted in its details. A disputed record may remain candidate.
Submitting a record
Send the following to security@agentcve.org. Do not send credentials, tokens, private keys or unredacted transcripts that contain them.
- What happened, in one paragraph: what the agent was asked to do, what it did instead, and what harm followed.
- The harness and its version, and the model, if known.
- The tools, permissions and approval mode the agent had (for example, auto-approve or a stored token).
- What the agent could reach: files, databases, credentials, accounts.
- Whether the harm was undone, by whom, and how long it took.
- First-hand sources: your own post, issue, post-mortem or transcript, with links.
- Whether you are the operator, the vendor, a researcher, or reporting someone else's account.
- How you would like to be credited, or whether you would rather not be named.
Decisions and disputes
Normal changes are proposed by pull request and require maintainer review. Advisory disputes are resolved from first-hand sources, the vendor advisory or reproducible evidence, with the reasoning recorded in the PR and validatedBy[] where appropriate. A withdrawal records status: withdrawn and a timestamp rather than erasing history. Security reports about ACVE itself follow SECURITY.md.
Ownership
CODEOWNERS requires the PickBits ACVE maintainers to review changes to advisories/ and spec/. Contributors retain credit for their work; advisory data is CC-BY-4.0.
Adding ecosystems and vulnerability classes
Propose a new ecosystem or vulnerability class in a PR to spec/, update the relevant schema/vocabulary and documentation, and include a focused node:test case. Use a real OSV package ecosystem when one exists. A new ACVE-specific ecosystem needs a stable identity and a clear reason a normal package identity cannot represent the condition.