Skip to content

Commit f18bc09

Browse files
Mike Morganclaude
andcommitted
docs: Add SECURITY.md with vulnerability reporting policy
- Supported versions table - Reporting process and response timelines - Scope definitions (in/out) - Safe harbor statement for security researchers - Security best practices 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <[email protected]>
1 parent 1b35eb4 commit f18bc09

File tree

1 file changed

+60
-0
lines changed

1 file changed

+60
-0
lines changed

SECURITY.md

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
| Version | Supported |
6+
| ------- | ------------------ |
7+
| 0.x.x | :white_check_mark: |
8+
9+
## Reporting a Vulnerability
10+
11+
**DO NOT** open a public GitHub issue for security vulnerabilities.
12+
13+
Instead, email: **[email protected]**
14+
15+
Include:
16+
- Description of the vulnerability
17+
- Steps to reproduce
18+
- Potential impact
19+
20+
### Response Timeline
21+
22+
| Timeline | Action |
23+
|----------|--------|
24+
| 24 hours | Initial acknowledgment |
25+
| 72 hours | Severity assessment |
26+
| 7 days | Status update |
27+
| 30 days | Target patch release |
28+
29+
### Scope
30+
31+
**In scope:**
32+
- Cortex CLI - Command injection, privilege escalation
33+
- API Key handling - Exposure, insecure storage
34+
- Sandbox escapes - Firejail bypass
35+
- Dependency vulnerabilities - Critical CVEs
36+
37+
**Out of scope:**
38+
- Third-party dependencies (report to maintainers)
39+
- Social engineering attacks
40+
- Denial of service (unless trivially exploitable)
41+
42+
### Safe Harbor
43+
44+
Security research conducted in good faith is authorized. We will not pursue legal action against researchers who:
45+
- Avoid privacy violations
46+
- Don't destroy data
47+
- Report findings promptly
48+
49+
## Security Best Practices
50+
```bash
51+
# Store API key securely
52+
read -s ANTHROPIC_API_KEY && export ANTHROPIC_API_KEY
53+
54+
# Always preview before executing
55+
cortex install <package> --dry-run
56+
```
57+
58+
## Contact
59+
60+

0 commit comments

Comments
 (0)