The Agent Lighthouse team and ForkPoint take security seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you find.
We provide security updates and patches for the following versions:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0.0 | ✅ |
| main | ✅ |
Please ensure you are using the latest version of @forkpoint/agent-lighthouse before reporting an issue.
Please do not report security vulnerabilities via public GitHub issues or discussions.
Instead, report vulnerabilities through one of the following channels:
You can report a vulnerability directly and privately through GitHub:
- Navigate to the Security Advisories tab of this repository.
- Click "Report a vulnerability" to open a private draft advisory.
If you are unable to use GitHub Security Advisories, send an email to:
- hello@forkpoint.com with the subject line
[SECURITY] Agent Lighthouse Vulnerability Report.
To help us triage and resolve the issue quickly, please provide:
- A description of the vulnerability and its potential impact.
- Affected package(s) (
@forkpoint/agent-lighthouse,core,report,mcp, or action). - Clear steps to reproduce the issue (proof-of-concept script, sample URL, or scan command).
- Any proposed mitigations or fixes, if available.
- Acknowledgment: We aim to acknowledge receipt of your report within 48 hours.
- Investigation: We will verify the vulnerability, evaluate its severity, and determine affected components within 5 business days.
- Remediation: We will work on a fix in a private fork or advisory workspace.
- Coordinated Disclosure: Once a patch is released to npm, we will publish a security advisory crediting you for the discovery (unless you prefer to remain anonymous).
We will not pursue legal action against researchers who report vulnerabilities in accordance with this policy and conduct security research in good faith:
- Do not exploit a vulnerability beyond what is necessary to demonstrate its presence.
- Do not access, modify, or destroy user data or third-party infrastructure.
- Give us reasonable time to remediate the vulnerability before public disclosure.