Skip to content

Security

Report a flaw

If you find a security flaw in Kiyesi, tell us privately first, so it can be fixed before anyone else knows about it.

Email security@kiyesi.dev.

When the agent’s code is published at release, you will also be able to use GitHub’s private vulnerability reporting on the Kiyesi repository.

Please do not open a public issue for a security flaw.

  • What the flaw is, and what someone could do with it.
  • The Kiyesi version and the system it ran on. Both are on the first lines of a report.
  • The steps to show it, as short as you can make them.

We reply to say the report arrived, work on a fix, and tell you before it is released. If you would like to be named when the fix is published, say so.