Agent Manifest Governance

Security policy

Scope

This repository hosts a declarative specification and reference examples for the Agent Manifest.

Although it is not an executable runtime system, security and safety considerations may still arise from:

Security concerns may originate not only from code, but from interpretation, implementation context, ecosystem adoption, or structural design decisions.

The scope of this policy includes both technical and structural risk.


Responsible Disclosure

Security and safety-related concerns must be reported privately.

Use GitHub’s Private Vulnerability Reporting mechanism for this repository
(Security → Advisories → Report a vulnerability).

Do not open a public issue for:

Public disclosure before coordinated review may increase harm.


What to Include in a Report

Please provide:

Reports that are specific and reproducible allow faster evaluation and resolution.


Evaluation Criteria

Reports will be assessed based on:

The Agent Manifest maintainers reserve the right to classify issues as:


Response Expectations

We aim to:

Response timelines may vary depending on severity, complexity, and contributor availability.

Critical risks may require silent patching before public communication.


Coordinated Disclosure

Where appropriate, coordinated disclosure may be conducted with:

The goal is harm minimization, not reputational management.


Limitations of the Specification

Agent Manifest is a declarative specification.

It does not:

Security responsibility ultimately resides with implementers, integrators, operators, and governance bodies deploying agent systems.

This repository provides structural guidance — not enforcement mechanisms.


Non-Authority Clause

The maintainers of Agent Manifest do not claim regulatory authority, compliance certification power, or operational control over third-party implementations.

Adoption of this specification does not imply endorsement, certification, or approval by the maintainers.


Good Faith Expectation

Security research conducted in good faith and reported responsibly is welcome.

Abusive, coercive, or exploitative behavior will not be engaged with publicly.


Agent Manifest prioritizes structural clarity over reactive expansion.
Security considerations are treated as architectural responsibilities, not afterthoughts.