Audit evidence
A 2026-08-27 audit of all nine active SagaSmith repositories found the same repository-security state everywhere:
- secret scanning: disabled
- push protection: disabled
- Dependabot security updates: disabled
- private vulnerability reporting: disabled
The organization SECURITY.md currently directs reporters to GitHub private vulnerability reporting first, so the documented primary path is not actually available. SagaSmith-agent/SECURITY.md also still identifies the project as NanoBot and points SagaSmith-specific reports to the upstream maintainers.
Affected repositories
Acceptance criteria
This issue tracks configuration and reporting only. It must not add tokens, secrets, or vulnerability details to public comments.
Audit evidence
A 2026-08-27 audit of all nine active SagaSmith repositories found the same repository-security state everywhere:
The organization
SECURITY.mdcurrently directs reporters to GitHub private vulnerability reporting first, so the documented primary path is not actually available.SagaSmith-agent/SECURITY.mdalso still identifies the project as NanoBot and points SagaSmith-specific reports to the upstream maintainers.Affected repositories
.githubSagaSmith-agentSagasmith-coreSagasmith-dndSagasmith-cocsagasmith-narrativeSagaSmith-serviceSagaSmith-dnd-content-librarySagaSmithAI.github.ioAcceptance criteria
SECURITY.mdto a working private channel before advertising it.This issue tracks configuration and reporting only. It must not add tokens, secrets, or vulnerability details to public comments.