Last updated: 2026-08-06
Spirit is a local, tool-using coding agent (Desktop, CLI, server, and shared runtime packages). If you find a security vulnerability in this project, please report it privately.
Do not open a public GitHub issue, pull request, or discussion for security vulnerabilities.
Use the Report a vulnerability button on this repository’s Security tab:
https://github.com/SpiritAgents/spirit/security/advisories/new
We use GitHub’s private vulnerability reporting so details stay confidential until a fix is ready.
- Affected component (Desktop, CLI, server, agent-core, host-internal, acp-server, etc.)
- Steps to reproduce
- Impact assessment (what an attacker could do)
- Proof of concept, if available
We acknowledge reports, assess severity, and work on a fix. We coordinate disclosure with reporters when a patch or mitigation is available.
We prioritize fixes on main and the latest release.
Issues in third-party model providers, MCP servers, or other external services you configure should be reported to those vendors directly.