Skip to content

Security: echopath-labs/forgerail

Security

SECURITY.md

Security

Report suspected ForgeRail vulnerabilities privately to the EchoPath Labs maintainers before public disclosure.

ForgeRail workspace diagnosis is read-only by default and must not inspect secrets, credentials, broad private archives, or unrelated child repositories. Capability Packs that access remote systems must declare identity, permissions, approval, validation, and rollback boundaries.

Do not include credentials, private project memory, production configuration, or customer data in issues, fixtures, receipts, or public bundles.

There aren't any published security advisories