Skip to content

Security: OWASP/Agent-Security-Regression-Harness

Security

SECURITY.md

Security Policy

Reporting security issues

Do not report security vulnerabilities through public GitHub issues.

For now, report security concerns to the project leader:

If the issue involves OWASP infrastructure or project governance, follow the relevant OWASP reporting process.

What counts as a security issue

Examples include:

  • A vulnerability in the harness implementation
  • Unsafe behavior in demo environments
  • Accidental exposure of secrets in test fixtures
  • Unsafe default configuration
  • Supply chain risks in project dependencies
  • A scenario that encourages harmful real-world execution instead of controlled testing

What does not count as a security issue

The following should usually be reported as normal GitHub issues:

  • Documentation bugs
  • Missing scenario categories
  • CLI usability problems
  • False positives or false negatives in assertions
  • Feature requests

There aren't any published security advisories