If you discover a security vulnerability in this repository's code or tooling:
- Do not open a public issue.
- Use GitHub Security Advisories (private report) in this repository.
- If private advisories are unavailable, open an issue with minimal detail and request a private contact channel.
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
Target response time: within 72 hours.
This repository is for defensive and educational research. If you discover a vulnerability in an external AI system:
- Follow responsible disclosure practices
- Contact the affected vendor's security team
- Allow reasonable patching time (typically 90 days)
- Avoid public disclosure before remediation
- Security issues in tools and scripts in this repository
- Vulnerable defaults or unsafe behaviors in included examples
- Documentation errors that could cause unsafe use
- Vulnerabilities in third-party/commercial AI services
- Feature requests
- General AI security discussions (use Discussions)
Security fixes are:
- Committed to
main - Noted in
CHANGELOG.md - Published via Security Advisory when appropriate
- Use this project only on systems you own or are authorized to test.
- Follow applicable laws and regulations.
- Do not use these techniques to cause harm.
Last updated: February 2026