Reference

Security policy

How to report vulnerabilities in Talos itself.

Talos is a security tool. Vulnerabilities in it matter to us — please report them privately before disclosing publicly.

Reporting

  • Email security@talos.dev with a description and a proof of concept.
  • We acknowledge within 2 business days and aim to fix or mitigate within 30 days.
  • We credit reporters in the changelog unless anonymity is requested.

Scope

  • The talos-redteam PyPI package.
  • Adapter code shipped in this repo.
  • Report templates and their rendering.
Out of scope
Findings the tool produces about your agent are, by design, not vulnerabilities in Talos. Those belong in the report Talos generated.