Security policy¶
Please report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue.
You'll get a reply within 3 days. A confirmed issue gets a fix within 7 days where possible, and a published advisory once a release is out.
Areas that matter most in this SDK: SSRF through push notification URLs or file url parts, task access across owners, Agent Card signature checks, and authentication handling in the transports.