| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public GitHub issue
- Email: security@agentralabs.tech
- Include: description, reproduction steps, impact assessment
- You will receive a response within 48 hours
- All MCP inputs are validated; invalid parameters return explicit errors
- Per-project isolation prevents cross-project state contamination
- Server profile requires
AGENTIC_TOKENfor authentication - No arbitrary code execution from .awf files
- Checkpoint data is scoped to project hash
- Installer uses merge-only MCP config updates (never overwrites)
This policy covers the AgenticWorkflow codebase and its release artifacts. Third-party dependencies are monitored via cargo audit.