SagaSmithAI
GitHub
导航Menu

安全Security

敏感问题,请私密报告。Report sensitive issues privately.

不要在公开 Issue、Pull Request、日志或截图中放入漏洞利用细节、token、cookie、provider 响应、私有战役、个人数据、商业来源材料或受限 Pack 内容。Do not put exploit details, tokens, cookies, provider responses, private campaigns, personal data, commercial source material, or restricted Pack content in public issues, pull requests, logs, or screenshots.

选择拥有边界的仓库Choose the repository that owns the boundary

如果问题属于 SagaSmith Web 的账户、session、API/BFF、托管 worker、Forge、Module Studio 或部署基础设施,请使用 Web 仓库的 GitHub Private Vulnerability Reporting。For SagaSmith Web accounts, sessions, API/BFF, hosted workers, Forge, Module Studio, or deployment infrastructure, use the Web repository's GitHub Private Vulnerability Reporting.

私密报告 SagaSmith Web 漏洞Privately report a SagaSmith Web vulnerability

如果问题属于 Agent、Core、D&D、CoC、Narrative 或内容目录,请先打开对应仓库的 SECURITY.md 或组织安全入口,并遵循其当前私密渠道。For Agent, Core, D&D, CoC, Narrative, or the content catalog, open the matching repository's current SECURITY.md or the organization security entry point and follow its private channel.

组织安全政策Organization security policy

请提供最少且可用的证据Provide minimal, usable evidence

  • 受影响的仓库与 commit/release;Affected repository and commit or release;
  • 受影响的信任边界与最小复现;Affected trust boundary and minimal reproduction;
  • 操作系统、Python/Node 版本与脱敏错误;Operating system, Python and Node versions, and redacted errors;
  • 不会暴露其他人的战役、账户或来源内容的证明材料。Evidence that does not expose another person's campaign, account, or source content.

不要测试他人的生产数据Do not test against someone else's production data

未经明确授权,不要访问他人的 campaign、账户或部署,也不要扩大最小复现。找不到安全的私密渠道时,先通过组织安全政策中列出的联系入口说明“存在敏感问题”,不要公开细节。Without explicit authorization, do not access another person's campaign, account, or deployment, and do not expand a minimal reproduction. If no safe private channel is available, use the organization security policy's contact path to report that a sensitive issue exists without publishing details.