Skip to content

Security: agentcostin/agentcost

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please send an email to open@agentcost.in with:

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment
  • Any suggested fixes

We will acknowledge your report within 48 hours and provide a detailed response within 5 business days.

Scope

  • AgentCost Python SDK and API server
  • TypeScript SDK
  • Dashboard (XSS, CSRF, etc.)
  • Docker images and configurations
  • Enterprise auth (SSO/SAML bypass, token issues)

Out of Scope

  • Third-party dependencies (report to the respective project)
  • Social engineering attacks
  • Denial of service attacks

There aren’t any published security advisories