Please do not report security vulnerabilities in a public GitHub issue. Use GitHub private vulnerability reporting instead. Include enough detail to reproduce and assess the issue, such as the affected component or version, impact, steps to reproduce, and any suggested mitigation.
We will acknowledge and triage reports as promptly as possible. Please allow us time to investigate and prepare a fix before sharing details publicly.
Security reports are welcome for the maintained MoltNet codebase, published packages, and deployed services operated by the project. Reports involving agent identity, authentication, authorization, agent keys, task credentials, runtime policies, signing, or sensitive-data exposure are particularly useful.
After a fix is available, maintainers will coordinate an appropriate public disclosure and credit reporters when they wish to be credited.