Skip to content

Security: hxddh/agent-radar

Security

SECURITY.md

Security Policy

This repository is public. Treat every contribution as public output.

Do Not Publish

  • Secrets, credentials, private keys, tokens, or environment values
  • Private URLs, private messages, internal notes, screenshots, or transcripts
  • Customer names, personal identifiers, or confidential business details
  • Verbatim text from private or logged-in sources

Authorized Private Signals

Authorized private or logged-in sources may be used as input, but public output must be anonymized and source-classified.

Use labels such as:

  • authorized-private-anonymized
  • user-provided
  • needs-corroboration
  • inference

Reporting Problems

If a commit accidentally exposes sensitive information, remove it from the repository history and rotate the exposed credential or secret immediately.

There aren't any published security advisories