Security fixes are prepared for the latest released minor line. Older versions may receive guidance but are not guaranteed patches.
Do not open a public Issue containing a vulnerability, secret, private repository path, raw Agent transcript, unredacted command output, or sensitive Evidence Bundle.
Use GitHub's private vulnerability reporting for
AdvancingTitans/agent-engineering-toolkit. If that setting is unavailable,
open a minimal public Issue asking for a private contact channel without
including technical details.
Include the affected version, platform, minimal reproduction, impact, and whether the problem crosses AET's local/read-only or explicit-execution boundary. Maintainers will acknowledge a valid private report as capacity allows; no fixed disclosure or patch deadline is promised.
AET redaction is defense in depth, not permission to publish sensitive input.