Skip to content

Security: IsaacCavallaro/agent-evals-workbench

Security

SECURITY.md

Security Policy

Supported Scope

Most of my public repositories are small portfolio projects, demos, prototypes, or learning projects. Unless a repository states otherwise, only the default branch of actively maintained repositories is in scope for security reports.

Project type Security support
Actively maintained apps, CLIs, and libraries Best-effort review and fixes
Archived repositories Not supported
Experimental prototypes Best-effort review only
Forks or third-party deployments Not supported

Reporting a Vulnerability

Do not publish exploit details in a public issue or pull request.

Preferred reporting path:

  1. Use GitHub private vulnerability reporting when it is enabled for the affected repository.
  2. If private vulnerability reporting is not available, contact me through a private channel linked from my GitHub profile and include the affected repository name.

Please include:

  • Affected repository and branch.
  • Vulnerability type and impact.
  • Reproduction steps or proof of concept.
  • Whether the issue affects a live deployment.
  • Any suggested mitigation.

Response Expectations

I will review valid reports on a best-effort basis. For portfolio and prototype repositories, the likely outcome may be a fix, a dependency update, a configuration change, or clearer documentation about the project boundary.

Out of Scope

  • Automated dependency reports without an exploitable path.
  • Social engineering.
  • Denial-of-service testing against live services.
  • Reports requiring access to private systems, private data, or third-party accounts.

There aren't any published security advisories