generated: '2026-08-19' method: searched probe: true source: https://github.com/agntcy/dir/blob/main/SECURITY.md policy: - https://github.com/agntcy/dir/blob/main/SECURITY.md - https://github.com/agntcy/oasf/blob/main/SECURITY.md - https://github.com/agntcy/dir-mcp/blob/main/SECURITY.md contact: - security@agntcy.org bug_bounty: null coordination: GitHub Security Advisories. Downstream maintainers and users can request participation by emailing security@agntcy.org. advisories: Announced via project GitHub Release notes, e.g. https://github.com/agntcy/dir/releases well_known_security_txt: false note: The policy is real and uniformly worded across AGNTCY repositories, but it is published only as SECURITY.md inside each repo — /.well-known/security.txt returned 404 on every AGNTCY host (see well-known/agntcy-well-known.yml). Adding an RFC 9116 security.txt is the cheapest open gap on this profile. evidence: - source: https://github.com/agntcy/dir/blob/main/SECURITY.md kind: security-policy status: 200 - source: https://github.com/agntcy/oasf/blob/main/SECURITY.md kind: security-policy status: 200 - source: https://agntcy.org/.well-known/security.txt kind: security.txt status: 404