Skip to content

Security: jasoncavinder/GuiltyParty

Security

SECURITY.md

Security Policy

Project Status

Guilty Party is in pre-release development. No production release or supported release series exists yet.

Reporting a Vulnerability

Do not report suspected vulnerabilities in a public issue, discussion, or pull request.

Use GitHub's private vulnerability reporting feature for this repository:

  1. Open the repository's Security tab.
  2. Select Report a vulnerability.
  3. Provide a concise description, affected area, reproduction details, and potential impact.

Remove unnecessary personal data, private communications, character secrets, creator content, credentials, and production data from the report. Use minimal synthetic examples whenever possible.

Response Expectations

Reports will be evaluated privately. Response and remediation timelines are not yet guaranteed while the project is pre-release.

The project owner may request additional reproduction details, coordinate a fix, and discuss disclosure timing through the private report. Public disclosure should wait until the issue has been assessed and a safe disclosure plan has been agreed.

Scope

Security-sensitive areas include:

  • authorization for character secrets, objectives, and hidden evidence
  • private messages, whispers, voice, video, and captions
  • account, session, pairing, and device identity
  • creator content and scenario access
  • session journal integrity and replay
  • AI Stage Manager data access
  • recording, consent, retention, and deletion behavior

This policy does not grant permission to access other people's accounts or data, degrade service, perform social engineering, or retain private information.

There aren't any published security advisories