ACVEAgent configuration vulnerability registry

Governance

PickBits maintains ACVE, its schemas, CLI, and public registry. There is currently one maintainer, who is responsible for releases, repository permissions, and the final status of advisories. Until a second maintainer joins, changes are merged by that maintainer after CI passes; the merge history shows this.

Editorial policy

ACVE records the configuration in which an AI agent, pursuing a goal, did harm: the harness, model, goal, tools and approval involved, what the agent could reach, and how pursuing the goal turned into harm. These behaviour records are the registry's main list.

Product defects and malicious packages that put agents at risk are kept as related flaw records. A defect that has a CVE and needs no agent misbehaviour is already covered by CVE and OSV; when ACVE deliberately leaves one out, it is listed in advisories/EXCLUDED.json with the reason.

Sources:

Records are drafted with AI coding agents, including Claude Code and Codex, and reviewed by the maintainer before they are published. The same evidence rules apply to every vendor, including the makers of those agents.

Conflicts of interest

PickBits builds its own software with AI coding agents, including Claude Code and Codex, and pays for them as a customer. PickBits has no investment in, partnership with, or sponsorship from any vendor named in the registry. The registry names products from those vendors and their competitors. To keep that from shaping the records:

Notice and right of reply

Records are built from public sources and go live after review; the named parties are not notified in advance. When a record names a product's maker, or a party that controls the harm such as an infrastructure provider, the maintainer sends that party's published security or press contact a link to the record when it goes live.

The party may reply at any time. A public reply is recorded in occurrence.responses with its status (acknowledged, fixed or disputed) and a link. A reply sent privately is quoted in the record only with the sender's permission. A reply that shows a fact is wrong, with a source, is corrected in the record; the record's modified date changes and the correction is noted in its details. A disputed record may remain candidate.

Submitting a record

Send the following to security@agentcve.org. Do not send credentials, tokens, private keys or unredacted transcripts that contain them.

  1. What happened, in one paragraph: what the agent was asked to do, what it did instead, and what harm followed.
  2. The harness and its version, and the model, if known.
  3. The tools, permissions and approval mode the agent had (for example, auto-approve or a stored token).
  4. What the agent could reach: files, databases, credentials, accounts.
  5. Whether the harm was undone, by whom, and how long it took.
  6. First-hand sources: your own post, issue, post-mortem or transcript, with links.
  7. Whether you are the operator, the vendor, a researcher, or reporting someone else's account.
  8. How you would like to be credited, or whether you would rather not be named.

Decisions and disputes

Normal changes are proposed by pull request and require maintainer review. Advisory disputes are resolved from first-hand sources, the vendor advisory or reproducible evidence, with the reasoning recorded in the PR and validatedBy[] where appropriate. A withdrawal records status: withdrawn and a timestamp rather than erasing history. Security reports about ACVE itself follow SECURITY.md.

Ownership

CODEOWNERS requires the PickBits ACVE maintainers to review changes to advisories/ and spec/. Contributors retain credit for their work; advisory data is CC-BY-4.0.

Adding ecosystems and vulnerability classes

Propose a new ecosystem or vulnerability class in a PR to spec/, update the relevant schema/vocabulary and documentation, and include a focused node:test case. Use a real OSV package ecosystem when one exists. A new ACVE-specific ecosystem needs a stable identity and a clear reason a normal package identity cannot represent the condition.