Skip to content

Security: wang2122/sprix-agent-spectra

Security

SECURITY.md

Security policy

SPECTRA is a research prototype and must not be the sole gate for high-impact deployment decisions.

Please report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue containing credentials, private task data, prompt-injection payloads that expose secrets, or details that enable active exploitation.

Production operators should sandbox evaluated agents, use least-privilege tool credentials, redact evidence artifacts, pin task/environment versions, and validate all evaluator inputs.

There aren't any published security advisories