Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: AgentWorkforce/relay

SECURITY.md

Security Policy

Agent Relay moves messages, credentials, and tool invocations between autonomous agents. A defect here can expose a workspace to agents — or people — that should never have reached it, so we treat security reports as a priority over feature work.

Reporting a vulnerability

Report privately through GitHub Security Advisories:

https://github.com/AgentWorkforce/relay/security/advisories/new

That form is visible only to the maintainers until an advisory is published, and it lets us open a private fix branch and credit you on release.

Please do not report vulnerabilities through public GitHub issues, pull requests, or the Discord server. Those are public the moment you post, which puts every workspace running the affected version at risk before a fix exists.

If GitHub Security Advisories is unavailable to you, open a public issue that says only that you have a security report and asks for a private channel — no details, no reproduction steps — and a maintainer will follow up.

What to include

The more of this you can provide, the faster we can confirm and fix:

  • The affected component and version (agent-relay --version, the npm package and version, or the broker build).
  • The type of issue (authentication bypass, credential disclosure, injection, privilege escalation across agents, denial of service, and so on).
  • Step-by-step reproduction, ideally as a minimal workspace or script.
  • The impact: what an attacker gains, and what access they need to start.
  • Any proof-of-concept code, logs, or transcripts.

Redact credentials before you send them. Workspace keys, broker keys, observer tokens, API keys, and OAuth tokens frequently appear in Relay logs and terminal transcripts. Replace them with placeholders. If a report requires a live credential to demonstrate, say so and we will arrange a channel for it rather than having it sit in an advisory thread.

What to expect

  • Acknowledgement: we aim to confirm receipt within 3 business days.
  • Assessment: we aim to confirm or dispute the report, with a severity assessment, within 10 business days.
  • Updates: we will keep you posted on remediation progress, and will tell you if a fix is going to take longer than expected.
  • Disclosure: we publish an advisory once a fixed version is available. We will credit you by name or handle unless you prefer otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We do not run a paid bug bounty.

Supported versions

We investigate reports against any release on the lines below. Fixes ship only at the head of that line: we do not patch earlier minors in place, and we do not backport across majors. If you are running an older 11.x, upgrading to the current 11.x is how you receive the fix.

ComponentReports investigatedFix delivered in
agent-relay CLI and @agent-relay/* packagesany 11.xlatest 11.x
agent-relay-broker crateany 3.xlatest 3.x

Releases before 11.0 (CLI and packages) and before 3.0 (broker) are unsupported — we will not investigate a report that reproduces only there. Upgrade before reporting against an older release; the issue may already be fixed.

Scope

In scope:

  • The agent-relay CLI and the published @agent-relay/* npm packages.
  • The agent-relay-broker Rust crate and its prebuilt platform binaries.
  • The message protocol itself: authentication, authorization between agents, workspace and channel isolation, delivery integrity, action routing.
  • Credential handling: how keys and tokens are stored on disk, passed to spawned harnesses, and surfaced in output, logs, and error text.
  • Agent-to-agent trust boundaries, including prompt or tool injection that crosses from message content into another agent's privileged actions.

Out of scope:

  • Vulnerabilities in third-party agent harnesses (Claude Code, Codex, Gemini CLI, and others). Report those to their maintainers; tell us if Relay's integration makes an existing harness issue materially worse.
  • Findings that require an attacker to already hold the same local user account as the agent process. Weaknesses that let a different local user or process reach agent state — group- or world-readable key files, permissive directory modes, predictable paths in shared temp directories — are in scope.
  • Dependency advisories with no demonstrated exploit path through Relay. We track these through automated scanning; a report is welcome if you can show the path.
  • Missing hardening headers, TLS configuration, or similar findings on the marketing site, absent a concrete impact.
  • Reports generated by automated scanners with no validation or reproduction.

Security tooling

.github/workflows/security.yml runs on pushes to main, on pull requests targeting main, and weekly. Coverage is not uniform, so it is worth being precise about what actually runs:

  • Gitleaks secret scanning runs on every trigger.
  • CodeQL, npm audit, and license compliance run only when a change touches the Node toolchain, so docs-only and Swift-only changes skip them.
  • Dependency review runs on pull requests only.
  • CodeQL analyzes JavaScript and TypeScript only. The agent-relay-broker Rust crate is in scope for this policy but is not covered by CodeQL.
  • Several of these jobs are advisory rather than blocking, so a green run does not by itself mean no findings.

Automated scanning catches regressions in the paths it covers. It is not a substitute for the reports we get from you, and the gaps above are exactly where your reports matter most.

There aren't any published security advisories