Report security issues privately to sam@thedataplant.com. Do not open a public issue for security vulnerabilities.
Include:
- The component affected (an engine spec, a doc, or a product)
- Steps to reproduce
- Impact assessment if known
We will acknowledge reports as quickly as possible and coordinate a fix and disclosure timeline with you.
The Gaia, Relay, and Swarms applications ship from their own repos. Report product vulnerabilities privately through the security advisory form on the matching repo (meterless/gaia, meterless/relay, meterless/swarms), or to the email above.
Meterless products execute locally and can automate desktop workflows. Reports involving privilege escalation, sandbox escape, prompt-injection-driven execution, or exfiltration of local context and memory are especially valuable.