Skip to content

Security: zhangj012595-cloud/AgentWorkspaceOS

Security

SECURITY.md

Security Policy

Public repository boundary

This repository must not contain:

  • passwords, API keys, app secrets, tokens, recovery codes, private keys, or auth cookies
  • real user OpenIDs, emails, phone numbers, addresses, or third-party contact records
  • raw private conversations or sensitive project memory
  • local credential files, keychains, OAuth payloads, or machine-specific private configuration
  • private hot-cache contents, internal task state, and project-specific agent handoffs

Examples and commands must use placeholders. Credentials should remain in the underlying CLI configuration, environment, or operating-system keychain.

Reporting a problem

If you find a credential or private identifier in the repository, do not include the value in a public issue. Contact the repository owner privately, remove the material from the working tree and Git history, and rotate or revoke the affected credential.

Scope

AgentWorkspaceOS is currently a protocol MVP. It does not claim enterprise compliance, hardened multi-tenant isolation, or formal security certification.

There aren't any published security advisories