Skip to content

Security: SpiritAgents/spirit

SECURITY.md

Security Policy

Last updated: 2026-08-06

Spirit is a local, tool-using coding agent (Desktop, CLI, server, and shared runtime packages). If you find a security vulnerability in this project, please report it privately.

Reporting a vulnerability

Do not open a public GitHub issue, pull request, or discussion for security vulnerabilities.

Use the Report a vulnerability button on this repository’s Security tab:

https://github.com/SpiritAgents/spirit/security/advisories/new

We use GitHub’s private vulnerability reporting so details stay confidential until a fix is ready.

What to include

  • Affected component (Desktop, CLI, server, agent-core, host-internal, acp-server, etc.)
  • Steps to reproduce
  • Impact assessment (what an attacker could do)
  • Proof of concept, if available

What we do

We acknowledge reports, assess severity, and work on a fix. We coordinate disclosure with reporters when a patch or mitigation is available.

Supported versions

We prioritize fixes on main and the latest release.

Out of scope

Issues in third-party model providers, MCP servers, or other external services you configure should be reported to those vendors directly.

There aren't any published security advisories