Security
Reporting a vulnerability
If you find a vulnerability in the MentorAgent packages on NuGet or in this website, please report it privately by writing to security@mentoragent.net.
Please include:
- what is affected: the package and version, or the page address;
- how to reproduce it, step by step, with a minimal example if you can;
- what an attacker could do with it;
- how we can reach you if we have questions.
Please don't make the details public until a fix is available.
While testing
- Test only against your own installations and your own data.
- Don't try to access other people's data, and don't disrupt this site: no load or denial-of-service tests, no spam.
Out of scope
- Applications that others build with MentorAgent: report the problem to their developers.
- Microsoft Agent Framework and the other dependencies: report it to their maintainers. If the problem also affects MentorAgent, let us know too.
What happens next
Reports go straight to the people who maintain the library, and we may write back to ask for details. When a fix is ready, we release it in a new version on NuGet and mention it in What's new. We don't run a bug bounty program.
We don't publish a PGP key. If the details are sensitive, send us a short description first and we'll agree with you on how to share the rest.
The machine-readable version of this page is at /.well-known/security.txt (RFC 9116 (external site)). What you send us is handled as described in the privacy notice.
