agentutils

POLICY / PUBLIC BETA

Security

Report vulnerabilities privately to security@agentutils.uk. Include the affected endpoint, impact, reproduction steps, and a safe proof of concept.

Scope

The currently deployed v1 Worker is in scope. Social engineering, denial-of-service testing, accessing other users' capability URLs, and testing third-party targets through the header checker are not permitted.

Disclosure

Allow reasonable time to investigate and remediate before public disclosure. AgentUtils has no bug-bounty program or guaranteed response time.

The security and abuse mailboxes become operational after a forwarding destination is verified through Cloudflare Email Routing.

Effective 7 August 2026