Do not open a public issue for a suspected vulnerability.
Report it privately through GitHub Security Advisories. Include the affected component, impact, reproduction steps, and any suggested mitigation. Remove secrets, credentials, personal data, and unrelated customer data from the report.
The maintainers will acknowledge the report through the advisory, investigate it, and coordinate disclosure and remediation there.
Agent Studio's current development version is declared in VERSION,
the repository's single version source. The project has not published its first
tagged release. Until then, security fixes target the default branch. After
tagged releases begin, only the latest release line and the default branch will
receive security fixes. Older release lines are unsupported unless a release
notice explicitly says otherwise.