14 lines
595 B
Markdown
14 lines
595 B
Markdown
# Security
|
|
|
|
Lumbridge will launch shells and coding agents with the user's authority. That
|
|
makes process isolation, approval visibility, secret handling, and transcript
|
|
redaction core product behavior rather than optional hardening.
|
|
|
|
Do not report vulnerabilities in a public issue while the disclosure channel is
|
|
being established. For now, contact the repository owners privately through the
|
|
Lumbridge organization on git.karti.ai.
|
|
|
|
Never include real credentials, private prompts, source code, or terminal output
|
|
in a vulnerability report without first agreeing on a secure transfer method.
|
|
|