What we commit to
- No new attacks. Everything tested is a class already documented in public research.
- Harmless by construction. The only thing any hidden instruction can cause is a request to a canary address we own. No real data, no third parties.
- Coordinated timing. Before publishing a finding that reflects badly on a specific product and version, we notify your security team and wait 45 days.
- Filtering counts in your favour. If your agent stops loading our canaries, that shows up as better resistance, which is the point.
- Open method. Scoring, attribution and validity are documented on the methodology page, and the source is open.
Report an error or ask to coordinate
If a result mislabels your product, mixes versions, or overstates what the sample shows, tell us and we’ll check it again. We would rather be right than fast.
Contact the maintainers through the security contact in the repository’s SECURITY.md, or open a private advisory on the source repository. A machine-readable statement of intent lives at /.well-known/fineprint.txt on both the site and the canary host.
Disclosure log
Coordinated disclosures and how they were resolved will be listed here. Nothing has been published yet.