Please do not open a public issue for a vulnerability that could put users, repositories, credentials, agent environments, or downstream systems at risk.
Report security issues privately to:
rgxdev
hello@d-aaron.dev
Include, when possible:
- a clear description of the issue;
- affected files or rules;
- realistic impact;
- reproduction steps or an example failure mode;
- a proposed mitigation, if known.
Please avoid including real secrets, credentials, private repository data, or personal information in reports.
Security reports may include weaknesses in CodeCanon itself that could encourage unsafe agent behavior, omit an important trust boundary, weaken authorization or validation guidance, or create misleading security guarantees.
Because CodeCanon is instruction-based rather than an enforcement engine, it cannot guarantee that every coding agent will follow every rule correctly. Repository owners remain responsible for reviewing and verifying generated code in their own environment.
Please allow a reasonable opportunity to assess and address a valid vulnerability before public disclosure.