Guilty Party is in pre-release development. No production release or supported release series exists yet.
Do not report suspected vulnerabilities in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting feature for this repository:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Provide a concise description, affected area, reproduction details, and potential impact.
Remove unnecessary personal data, private communications, character secrets, creator content, credentials, and production data from the report. Use minimal synthetic examples whenever possible.
Reports will be evaluated privately. Response and remediation timelines are not yet guaranteed while the project is pre-release.
The project owner may request additional reproduction details, coordinate a fix, and discuss disclosure timing through the private report. Public disclosure should wait until the issue has been assessed and a safe disclosure plan has been agreed.
Security-sensitive areas include:
- authorization for character secrets, objectives, and hidden evidence
- private messages, whispers, voice, video, and captions
- account, session, pairing, and device identity
- creator content and scenario access
- session journal integrity and replay
- AI Stage Manager data access
- recording, consent, retention, and deletion behavior
This policy does not grant permission to access other people's accounts or data, degrade service, perform social engineering, or retain private information.