Skip to content

Security: turnerll/EloPhanto

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT open a public issue.
  2. Email: security@elophanto.com
  3. Include: description, reproduction steps, impact assessment.
  4. We will acknowledge within 48 hours.
  5. We will provide a fix timeline within 7 days.

Scope

  • Prompt injection that bypasses permission system
  • Credential leakage from vault
  • Unauthorized file access outside workspace
  • Gateway authentication bypass
  • MCP server privilege escalation
  • Skill security scanning bypass

Out of Scope

  • LLM hallucinations or incorrect outputs
  • Rate limiting on external APIs
  • Issues requiring physical access to the machine

Supported Versions

Only the latest release is supported with security fixes.

There aren't any published security advisories