ACOP

Security Policy

This repository contains a specification, not a running service. There is no deployment here to compromise. What is in scope is the possibility that the protocol itself specifies something unsafe — a requirement that, if implemented exactly as written, leaves conforming implementations vulnerable.

Reporting a vulnerability

Report privately through GitHub’s private vulnerability reporting rather than opening a public issue. Please do not disclose publicly until a fix or an advisory is published.

You should expect an initial response within 7 days.

In scope

Out of scope

Threat model assumptions

ACOP assumes workers are authenticated and that the coordination backend is the authority on claim ownership. It does not assume workers are mutually trusting or non-malicious. A report showing that an authenticated but hostile worker can violate the coordination guarantees — stealing a claim, forging completion evidence, or silently superseding another agent’s blackboard entry — is a valid specification vulnerability even though the attacker holds valid credentials.