Security

June 10, 2026 ยท View on GitHub

Reporting

Open a private security advisory on GitHub or contact the maintainers.

Fleet-specific risks

  • Unattended agents with broad MCP scopes
  • Shared credentials without identity model
  • Inbox bypass for destructive tools
  • Kill switch never tested

See docs/safety.md and docs/failure-modes.md.

Contents

  1. 1Reporting
  2. 2Fleet-specific risks