This repository is an independent AI context resource pack for VRSEN/agency-swarm. It is not Agency Swarm's official security contact.
Report pack-level security issues through a private GitHub security advisory when available, or by opening a minimal public issue that does not disclose exploitable details.
Pack-level security issues include:
- Instructions that encourage unsafe credential handling.
- Prompts that request secrets, tokens, private logs, or proprietary code without a clear need.
- Broken guardrails that cause an AI coding agent to run destructive commands without review.
- Misleading attribution or links that could route users to the wrong source.
Upstream product vulnerabilities should be reported to VRSEN/agency-swarm's own security policy. Link the upstream advisory here only when this pack needs a mitigation or warning.
There is no bug bounty program for this pack unless explicitly stated in this repository.