Please report security issues privately through GitHub's private vulnerability reporting:
- Go to the Security tab
- Click Report a vulnerability
- Describe the issue and, where relevant, how to reproduce it
This routes the report to the maintainers privately via a GitHub Security Advisory. Please do not open a public issue for a security report.
We aim to acknowledge a report within 7 days and to agree a disclosure timeline with you once the issue is confirmed.
This project ships prompt-based security-audit agents, not a running service, so "vulnerability" is broader than a code defect. In scope:
- False assurance — a prompt or methodology change that causes the auditor to report code as compliant when it contains a genuine ASVS violation, or to suppress a valid finding.
- Prompt injection — a way to make the agent follow instructions embedded in the code under audit rather than its own methodology (for example, hidden text that suppresses findings or alters the report).
- Fabricated findings presented with false evidence (file paths, line numbers, or requirement IDs that do not exist), where the cause is the shipped prompt rather than the model alone.
- Defects in the tooling under
tools/or.github/workflows/.
Incorrect ASVS requirement references, false positives, and ordinary agent misbehaviour are not security issues — please report those as a regular bug.
This is an actively maintained, single-track project: fixes land on main and
ship in the next tagged release. Only the latest release is supported.