If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue.
- Email: security@elophanto.com
- Include: description, reproduction steps, impact assessment.
- We will acknowledge within 48 hours.
- We will provide a fix timeline within 7 days.
- Prompt injection that bypasses permission system
- Credential leakage from vault
- Unauthorized file access outside workspace
- Gateway authentication bypass
- MCP server privilege escalation
- Skill security scanning bypass
- LLM hallucinations or incorrect outputs
- Rate limiting on external APIs
- Issues requiring physical access to the machine
Only the latest release is supported with security fixes.