Skip to content

Security: vukrosic/open-discovery

Security

SECURITY.md

Security policy

Open Discovery stores research instructions and evidence paths but does not sandbox or authorize experiment commands. Treat project files as untrusted input when connecting the harness to an AI agent or executor.

Do not place secrets, personal data, access tokens, private datasets, or regulated records in a public project. Keep external actions, spending, publication, human-subjects work, and destructive operations behind explicit authority checks in the environment that performs them.

Report vulnerabilities privately through the repository owner's GitHub security advisory page.

There aren't any published security advisories