Skip to content

Security: Prompthon-IO/agent-systems-handbook

SECURITY.md

Security Policy

This repository is the home of Prompthon Agentic Labs plus its tracked example projects. The main security-relevant surfaces are the tracked example code, workflow automation, and any repository configuration that affects how contributions are reviewed and merged.

Supported surfaces

Surface Supported
Current main branch content Yes
Example projects under lane-local examples/ folders on main Yes
Historical commits, abandoned branches, or forks No
Imported material under references/ No

Reporting a vulnerability

If GitHub private vulnerability reporting is enabled for this repository, use the repository's Report a vulnerability flow.

If private vulnerability reporting is not yet enabled:

  1. Do not open a public issue.
  2. Use the Prompthon IO community contact path in SUPPORT.md to request a private reporting channel.
  3. Share only a high-level description until a private channel is available.

Please include:

  • the affected path or workflow
  • the impact
  • clear reproduction steps
  • any proof-of-concept details needed to validate the report

Handling expectations

This repository is maintained on a best-effort basis. Reports that affect active example code, workflow security, or repository governance will be prioritized over historical or reference-only material.

There aren't any published security advisories