Skip to content

Security: cogniolab/agent-security

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

⚠️ Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in Agent Security Toolkit, please email:

dev@cogniolab.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

We will respond within 48 hours and work with you to address the issue.

Supported Versions

Version Supported
0.1.x

Security Features

Agent Security Toolkit provides:

  1. Prompt Injection Detection: ML-based detection of prompt injection attacks
  2. PII Redaction: Automatic removal of sensitive personal information
  3. Rate Limiting: Cost-aware rate limiting to prevent abuse
  4. Audit Logging: Security event logging for compliance
  5. Red Team Testing: Comprehensive security testing suite

Best Practices

When using Agent Security:

  1. Keep Updated: Always use the latest version
  2. Configure Properly: Use appropriate security thresholds for your use case
  3. Monitor Logs: Regularly review security logs
  4. Test Regularly: Run red team assessments periodically
  5. Follow Compliance: Use compliance templates for regulated industries

Disclosure Policy

We follow responsible disclosure:

  1. You report the vulnerability privately
  2. We confirm and investigate (48 hours)
  3. We develop and test a fix
  4. We release the fix
  5. We publicly disclose (after users have time to update)

Thank you for helping keep Agent Security secure!

There aren’t any published security advisories