We take the security of Neutree Agent Platform seriously. Thank you for helping keep the project and its users safe.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please report it privately through GitHub private vulnerability reporting: open the repository's Security tab → Report a vulnerability. This creates a private advisory visible only to you and the maintainers.
Please include, as far as you can:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
- Affected component(s) and version / commit.
- Any suggested mitigation.
- We aim to acknowledge your report within a few business days.
- We will investigate, keep you informed of progress, and coordinate a fix and disclosure timeline with you.
- We are happy to credit reporters in the advisory unless you prefer to remain anonymous.
Security issues in any first-party component of this repository are in scope. Vulnerabilities in third-party dependencies or external components (e.g. OpenSandbox) should be reported to their respective projects; if a NAP default or integration makes such an issue materially worse, we still want to hear about it.