Security policy
Reporting
Send reports to security@agentcve.org:
- a vulnerability in the ACVE CLI, schemas, redaction logic, registry sync, or a published build;
- an error in a record — a wrong version, identifier, severity, attribution or source.
No PGP key is published yet. To send something sensitive, email first without the details and ask for a secure channel.
To submit a new record rather than a correction, use the template in GOVERNANCE.md.
For a vulnerability, include the affected version or commit, reproduction steps, impact, and a minimal safe proof. For a record, include the advisory id and the source that contradicts it.
Reports are acknowledged as soon as practical. Fixes, credit and a disclosure date are coordinated with the reporter; we prefer an embargo until a patched release or mitigation exists, and shorten it when exploitation is under way. Corrections to records are published with the record, and withdrawn records stay visible with the reason.
Scope
The security boundary includes redaction, file access, matcher and audit decisions, archive extraction, network gating, and publication tooling. Runtime attacks against an agent are not a vulnerability in ACVE unless they demonstrate a defect in one of those boundaries.