Security Policy
The repository is educational and does not contain a supported production AgentPlane service. A vulnerable teaching example or unsafe publication workflow should still be reported responsibly.
Do not put live credentials, customer data or details targeting an unpatched live system in a public issue. Use GitHub private vulnerability reporting when enabled. Before public launch, the maintainer must enable that feature or document a real private contact channel. No address or service-level promise is invented here.
Include affected revision, example, expected boundary and a minimal safe reproduction. Tests must target your own disposable environment. Coordinated fixes should include a regression test and an edition note.
The included programs do not establish hostile-code containment. Read reports/VALIDATION.md for actual checks and limitations.