ACVEAgent configuration vulnerability registry

Security policy

Reporting

Send reports to security@agentcve.org:

No PGP key is published yet. To send something sensitive, email first without the details and ask for a secure channel.

To submit a new record rather than a correction, use the template in GOVERNANCE.md.

For a vulnerability, include the affected version or commit, reproduction steps, impact, and a minimal safe proof. For a record, include the advisory id and the source that contradicts it.

Reports are acknowledged as soon as practical. Fixes, credit and a disclosure date are coordinated with the reporter; we prefer an embargo until a patched release or mitigation exists, and shorten it when exploitation is under way. Corrections to records are published with the record, and withdrawn records stay visible with the reason.

Scope

The security boundary includes redaction, file access, matcher and audit decisions, archive extraction, network gating, and publication tooling. Runtime attacks against an agent are not a vulnerability in ACVE unless they demonstrate a defect in one of those boundaries.