generated: '2026-08-06' method: searched source: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf docs: https://www.agibot.com/filepage/282.html notes: AgiBot (Zhiyuan Robotics) publishes a full vulnerability disclosure policy — but as a PDF linked from the Document Center, not as an RFC 9116 /.well-known/security.txt. Every AgiBot host returns 404 for security.txt, so the policy is invisible to automated discovery. Publishing a security.txt pointing at this PDF and at security@agibot.com would make the existing programme machine-discoverable at no cost. x-evidence: fetched: '2026-08-06' url: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf http_status: 200 content_type: application/pdf bytes: 47903 program: published: true type: vulnerability disclosure policy (VDP) bug_bounty: false monetary_rewards: false reward_note: The policy states explicitly that AgiBot does not offer monetary rewards for vulnerability disclosures. platform: null safe_harbor: not stated contact: email: security@agibot.com method: email url: mailto:security@agibot.com policy_url: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf report_requirements: mandatory: - Title of vulnerability - Description of vulnerability with summary, supporting files and possible mitigations - Impact — what an attacker could do - Steps to reproduce as a benign, non-destructive proof of concept optional: - Asset (web address, IP address, product or service name) where the vulnerability can be observed - Weakness (CWE) - Severity (CVSS v3.0) - Reporter name and email address response_targets: acknowledgement: 5 working days triage: 10 working days status_enquiries: no more than once every 14 days remediation: prioritised by impact, severity and exploit complexity; reporter notified on remediation and may be invited to confirm the fix coordinated_disclosure: permitted: true note: Public disclosure requests are welcomed once the vulnerability is resolved, and must be coordinated with AgiBot so guidance to affected users is unified. prohibited_activity: - Breaking any applicable law or regulation - Accessing unnecessary, excessive or significant amounts of data - Modifying data in the Organization’s systems or services - Using high-intensity invasive or destructive scanning tools - Attempting or reporting any form of denial of service - Disrupting the Organization’s services or systems security_txt: present: false probed: - https://www.agibot.com/.well-known/security.txt - https://x2-aimdk.agibot.com/.well-known/security.txt - https://www.agibot.com.cn/.well-known/security.txt - https://store.agibot.com/.well-known/security.txt status: 404