POLICY / PUBLIC BETA
Security
Report vulnerabilities privately to security@agentutils.uk. Include the affected endpoint, impact, reproduction steps, and a safe proof of concept.
Scope
The currently deployed v1 Worker is in scope. Social engineering, denial-of-service testing, accessing other users' capability URLs, and testing third-party targets through the header checker are not permitted.
Disclosure
Allow reasonable time to investigate and remediate before public disclosure. AgentUtils has no bug-bounty program or guaranteed response time.
The security and abuse mailboxes become operational after a forwarding destination is verified through Cloudflare Email Routing.
Effective 7 August 2026