Architekton is a public experimental alpha and is not a security, compliance, or enforcement product. Reports can be incomplete and the schema can change before 1.0.
Please use GitHub Security Advisories and private vulnerability reporting through the repository's Security → Advisories → Report a vulnerability flow. Do not open a public issue for an undisclosed vulnerability.
If private vulnerability reporting is temporarily unavailable, contact hello@satyampariyar.com. Do not include secrets, credentials, private repository contents, or exploitable details in public messages.
- escaping the selected repository root
- following symlinks or reading excluded content
- executing repository-provided commands or hooks without authorization
- exposing secrets, environment values, or raw command bodies
- writing inside an inspected repository during inspection
- plugin packaging or installation behavior that violates the documented authority boundary
Reports about unsupported repository ecosystems, incomplete heuristics, or inaccurate non-security findings belong in the normal issue tracker.
Only the latest version available through the documented Architekton marketplace, sourced from the default branch, receives security fixes during the experimental alpha. No long-term support or compatibility window is promised before 1.0.