Reference
Security policy
How to report vulnerabilities in Talos itself.
Talos is a security tool. Vulnerabilities in it matter to us — please report them privately before disclosing publicly.
Reporting
- Email
security@talos.devwith a description and a proof of concept. - We acknowledge within 2 business days and aim to fix or mitigate within 30 days.
- We credit reporters in the changelog unless anonymity is requested.
Scope
- The
talos-redteamPyPI package. - Adapter code shipped in this repo.
- Report templates and their rendering.
Out of scope
Findings the tool produces about your agent are, by design, not vulnerabilities in Talos. Those belong in the report Talos generated.