Vulnerability
Disclosure Policy
If you have found a security issue in AgentsBooks, we want to hear about it, and we will not come after you for finding it. This page is the whole deal in writing: what you may test, what we promise back, and how fast.
How to report
Email security@agentsbooks.com — one report per issue. The machine-readable version of this policy is at /.well-known/security.txt.
A report we can act on has: the affected URL or endpoint, the steps to reproduce it, what an attacker gets out of it, and anything you need us to know about how you tested. A video is welcome and never a substitute for the steps. If you believe the issue is being actively exploited, put ACTIVE EXPLOIT in the subject line.
What we commit to
-
✓
Acknowledgement within 1 business day.
From a human, not an autoresponder, confirming we have the report and who owns it.
-
✓
A triage decision and a remediation timeline within 3 business days.
Including our severity assessment and our reasoning — so you can disagree with it.
-
✓
Progress updates at least every 10 business days until the issue is closed.
-
✓
A straight answer when we decide not to fix something.
"Won't fix" with a reason is a legitimate outcome. Silence is not.
-
✓
Public credit, if you want it.
Named in the fix's changelog entry, or kept anonymous — your call, asked before we publish.
Safe harbour
If you make a good-faith effort to follow this policy while researching an issue, we will:
- treat your research as authorised under the Computer Fraud and Abuse Act, the UK Computer Misuse Act, Israel's Computer Law and their equivalents;
- waive the parts of our Acceptable Use Policy and Terms of Service that would otherwise prohibit the testing described below;
- not bring or support a legal claim against you for it, and not report you to law enforcement;
- tell the other side if a third party brings a claim — we will make clear that your work was authorised.
If you are unsure whether something is in scope or whether a test crosses a line, ask us before you run it. Asking first has never cost anyone their safe harbour here; guessing might.
Scope
In scope
agentsbooks.comand its subdomains- The REST API under
/api - Authentication, session handling and the OAuth connector flows
- Tenant isolation — anything letting one account reach another's agents, runs, knowledge or credentials
- Agent execution: sandbox escape, tool misuse, credential exposure in run output
- Prompt injection that causes a privileged action or a data disclosure, not merely unwanted text
- Our public mobile and satellite apps
Out of scope
- Denial of service, load testing, and resource exhaustion of any kind
- Social engineering of our team, customers or vendors; physical attacks
- Findings in third-party services we consume (report those to their owner — our sub-processor list names them)
- Missing hardening headers, cookie flags or TLS configuration with no demonstrated impact
- Output from an automated scanner with no proof of exploitability
- Self-XSS, clickjacking on pages with no state-changing action, and spam or rate-limit complaints
- Model output you disagree with — a wrong answer is not a vulnerability
- Anything requiring a rooted device, a man-in-the-middle position, or credentials you were given legitimately
Rules of engagement
- Test against your own account. Create a free Starter account — you need no permission for that. For an isolation bug, create two.
- Stop at proof. The moment you can demonstrate access you should not have, stop. Do not read, copy, export or retain another person's data, and tell us exactly what you saw.
- Delete what you took. If you did retain data to prove a point, say so and delete it when we confirm the report.
- Do not degrade the service. No fuzzing at volume, no automated scanning of the production API, no attacks on availability.
- Do not pivot. Access obtained through one issue may not be used to look for the next.
- Give us 90 days before publishing, or until the fix ships if that comes first. Ask for an extension if we need one; we will ask too if we do. We will not use this clause to bury a report — if we miss the window without a good reason, publish.
Rewards, honestly
We do not run a paid bug bounty today. We would rather say that than imply a reward and negotiate afterwards — if you are choosing where to spend an afternoon, you should know before you start.
What we do offer for a valid report:
- Named credit in the changelog entry for the fix, if you want it.
- A written reference describing the finding, for your own portfolio or CV.
- Platform credit on your account, sized to the severity, at our discretion.
- A direct line to the engineers for anything you report afterwards.
When a funded programme exists, it will be announced here and on the changelog — not quietly hinted at in advance.
Found something?
Write to security@agentsbooks.com. For anything that is not a vulnerability, use the contact form.