# Security policy [中文](./SECURITY.zh-CN.md) ## Reporting a vulnerability Please avoid publishing exploitable details in a public issue before maintainers have had a chance to assess them. Use GitHub's private vulnerability reporting feature if enabled for the repository. Include: - affected version or commit; - reproduction steps; - impact; - suggested mitigation if known. ## Important scope note The `inspect` command is a heuristic static triage tool. Its output is not a security certification, sandbox, antivirus result, or guarantee that an Agent extension is safe to install.