Skip to content

docs: add a security policy - #477

Open
Yashasm18 wants to merge 1 commit into
andrewyng:mainfrom
Yashasm18:agent/add-security-policy
Open

docs: add a security policy#477
Yashasm18 wants to merge 1 commit into
andrewyng:mainfrom
Yashasm18:agent/add-security-policy

Conversation

@Yashasm18

@Yashasm18 Yashasm18 commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

What changed

Expanded the new root-level SECURITY.md into a repository-informed security policy. It now documents:

  • private vulnerability reporting and coordinated disclosure;
  • the local server token and browser-origin boundaries;
  • workspace roots, trust decisions, permission modes, and command approvals;
  • SecretStore handling and platform-specific file protections;
  • MCP OAuth loopback/state handling;
  • audit-log redaction and safe evidence sharing; and
  • report details tailored to connectors, malicious workspaces, local processes, browser pages, and prompt-injection paths.

Why

OpenWorker can operate on local files, run commands, use MCP/connectors, and send data to model providers. The policy now gives users and contributors a clearer way to recognize and report issues affecting those boundaries.

Validation

  • git diff --check
  • Documentation-only change; no runtime tests required.

@Yashasm18
Yashasm18 force-pushed the agent/add-security-policy branch from 8d98464 to 08cbb0c Compare August 9, 2026 03:33
@Yashasm18
Yashasm18 marked this pull request as ready for review August 9, 2026 03:34
lwxyfer added a commit to lwxyfer/openworker that referenced this pull request Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant