Security Policy
This repository contains a specification, not a running service. There is
no deployment here to compromise. What is in scope is the possibility
that the protocol itself specifies something unsafe — a requirement that,
if implemented exactly as written, leaves conforming implementations
vulnerable.
Reporting a vulnerability
Report privately through GitHub’s
private vulnerability reporting
rather than opening a public issue. Please do not disclose publicly until
a fix or an advisory is published.
You should expect an initial response within 7 days.
In scope
- A normative requirement whose correct implementation is insecure — for
example, a mandated flow that leaks a claim token, permits privilege
escalation across agents, or requires accepting an unauthenticated
mutation.
- Authentication or authorization guidance in
acop-http-binding.md that is exploitable as
specified.
- A claim, lease, or handoff sequence that allows one agent to take,
renew, or complete work owned by another without detection.
- A schema that admits a value an implementation would reasonably treat as
trusted but that the spec does not require to be validated.
- Conformance fixtures that would lead an implementer to certify an
insecure behavior as conformant.
Out of scope
- Vulnerabilities in the reference implementation. Those belong to
BogDB; the implementation is not
normative and its bugs are not spec bugs.
- Vulnerabilities in third-party implementations of ACOP. Report those to
the implementer. If the root cause turns out to be the specification,
we want to hear about it here as well.
- Deployment-level concerns the spec deliberately leaves open — choice of
identity provider, transport TLS configuration, and backend storage are
all explicitly implementation-defined.
Threat model assumptions
ACOP assumes workers are authenticated and that the coordination backend
is the authority on claim ownership. It does not assume workers are
mutually trusting or non-malicious. A report showing that an authenticated
but hostile worker can violate the coordination guarantees — stealing a
claim, forging completion evidence, or silently superseding another
agent’s blackboard entry — is a valid specification vulnerability even
though the attacker holds valid credentials.