Skip to content

Security: CinvanaAI/agent-workflow-governance

Security

SECURITY.md

Security posture

File assignments and per-tool permissions are policy records. This library does not open assigned paths during target preview, and its test uses a nonexistent synthetic path.

The executor uses a fixed action-kind dispatch table and records authorization, outputs, and failures. It is not an operating-system sandbox. Agent workflows with no capability packages produce bounded planning/evidence outputs; configured capability packages may execute trusted published Python through the same explicitly documented boundary used by Skeleton.

Do not load private agent memories or real credentials into a public checkout. The repository contains synthetic defaults only and the test deletes its temporary owner-record tree.

There aren't any published security advisories