Skip to content

Security: agenttrailhq/guardrails

Security

SECURITY.md

Security Policy

How to report

Email security@agenttrail.sh. Keep vulnerability details out of GitHub issues, pull requests, and discussions until a fix is released.

A useful report includes the rule id, the package version, the command or path involved, and what goes wrong, with secrets and private project details removed. Please confirm the problem still occurs on the latest npm release. We welcome coordinated disclosure and will work with you on timing.

In scope

  • A shipped rule whose pattern can be made to backtrack. The guard fails open under a time limit, so a slow pattern lets the command through rather than merely running slowly.
  • A problem with the published @agenttrail/guardrails package itself.

Problems in the tool that enforces these rules belong to AgentTrail Guard's security policy.

Out of scope

There aren't any published security advisories