generated: '2026-08-29' method: searched source: https://raw.githubusercontent.com/Significant-Gravitas/AutoGPT/master/SECURITY.md description: >- AutoGPT publishes a real, specific vulnerability disclosure policy — with named intake, an acknowledgement SLA and a coordinated-disclosure clock — but it lives in the GitHub repository's SECURITY.md, not on agpt.co. There is no /.well-known/security.txt on any AutoGPT host (all three probed 404 on 2026-08-29), so an automated scanner following RFC 9116 finds nothing. published: true policy_url: https://github.com/Significant-Gravitas/AutoGPT/blob/master/SECURITY.md intake: primary: https://github.com/Significant-Gravitas/AutoGPT/security/advisories/new mechanism: GitHub Security Advisory (private report) public_channels_forbidden: >- Public GitHub issues, discussions and pull requests are explicitly ruled out for vulnerability reports. acknowledgement_sla: 14 business days disclosure_policy: fix_window_days: 90 post_patch_update_window_days: 30 max_total_days: 120 quote: >- "Allow us a 90-day security fix window before any public disclosure. After patch is released, allow 30 days for users to update before public disclosure (for a total of 120 days max between update time and fix time)." reporting_process: - Submit the report through the GitHub Security Advisory intake. - AutoGPT acknowledges receipt within 14 business days. - Collaborate with the team to understand and validate the issue. - AutoGPT works on a fix and coordinates the release. supported_versions: - version: Latest release on master branch supported: true - version: Development commits (pre-master) supported: true - version: classic/ folder supported: false note: Declared legacy, unsupported and out of scope for security reports. - version: All other versions supported: false out_of_scope: - >- Any code under classic/ — "We will not address security vulnerabilities in this deprecated code." - >- The JWKS transport check (the startup warning when JWT_JWKS_URL is fetched over cleartext http:// from a non-local host). SECURITY.md states this is best-effort operator guidance, not a security boundary, and that reports it can be missed, silenced or evaded are not eligible for a CVE. bug_bounty: program: none note: >- SECURITY.md carries a COMMENTED-OUT Huntr.dev line (""). The bounty programme is disabled, not offered. Recorded as absent. related_program: name: GitHub Secure Open Source Fund (SOSF) evidence: https://agpt.co/blog/autogpt-partners-with-github-for-ai-security note: >- AutoGPT announced participation in GitHub's Secure Open Source Fund on its own blog. This is a security-investment programme, not a disclosure channel or a certification. probes: - url: https://raw.githubusercontent.com/Significant-Gravitas/AutoGPT/master/SECURITY.md status: 200 - url: https://agpt.co/.well-known/security.txt status: 404 - url: https://platform.agpt.co/.well-known/security.txt status: 404 - url: https://backend.agpt.co/.well-known/security.txt status: 404 recommendation: >- Publishing an RFC 9116 /.well-known/security.txt on agpt.co with Policy: and Contact: pointing at the existing GitHub advisory intake would take one file and make an already-good policy machine-discoverable. maintainers: - FN: Kin Lane email: kin@apievangelist.com