generated: '2026-09-14' method: searched source: https://github.com/automotive-grade-linux/lava-mcp-toolkit/blob/main/SECURITY.md published: true scope: >- Repository-scoped, not project-wide. AGL publishes a written vulnerability disclosure policy for lava-mcp-toolkit - its first-party MCP server - covering all four language implementations, the Docker/Caddy setup and the helper scripts. No project-wide security policy for the AGL platform itself (meta-agl, the agl-service-* bindings, the SoDeV reference platform) was found, and no /.well-known/security.txt is served on any AGL host (all six hosts probed returned 404). channels: - type: private-security-advisory detail: >- Preferred channel. AGL asks reporters to open a private security advisory on the repository (GitHub: Security > Advisories > "Report a vulnerability") rather than a public issue, so there is time to fix before disclosure. url: https://github.com/automotive-grade-linux/lava-mcp-toolkit/security/advisories - type: maintainer-contact detail: Fallback - contact the maintainer listed in the repository metadata directly, with enough detail to reproduce. required_report_contents: - which language and variant is affected (e.g. "rust/server") - the affected files or endpoint - a reproduction - the impact as the reporter assesses it in_scope: - anything letting an unauthenticated or under-authenticated caller reach a LAVA token, another MCP user's identity, or the /admin/reload endpoint - request data (job ids, hostnames, query strings, job definition YAML) escaping its parameter into a shell command or HTTP header injection - denial of service specific to this code, such as unbounded memory growth reading a request - supply-chain concerns in the pinned dependencies recorded in sbom/ out_of_scope: - vulnerabilities in LAVA itself, lavacli, curl, caddy or base Docker images (report upstream; a linking note here is welcomed) - issues requiring the attacker to already hold a valid MCP or LAVA token for the identity being attacked - the stated trust boundary - documented known limitations, e.g. no keep-alive in the C++/Rust HTTP servers bug_bounty: offered: false detail: No HackerOne, Bugcrowd or Intigriti program was found for AGL. supported_versions: detail: >- AGL states the toolkit has no maintained release branches yet; there is one version, 0.1.0 (2026-08-27), and fixes land on main. security_txt: served: false hosts_probed: - host: www.automotivelinux.org status: 404 - host: automotivelinux.org status: 404 - host: docs.automotivelinux.org status: 404 - host: lava.automotivelinux.org status: 404 - host: gerrit.automotivelinux.org status: 404 - host: git.automotivelinux.org status: 404 recommendation: >- An RFC 9116 /.well-known/security.txt on www.automotivelinux.org pointing at the same advisory channel would make this policy discoverable at the domain level, where a scanner or agent looks for it, instead of only inside one repository. related: threat_model: https://github.com/automotive-grade-linux/lava-mcp-toolkit/blob/main/docs/security.md sbom: https://github.com/automotive-grade-linux/lava-mcp-toolkit/tree/main/sbom cra_mapping: https://github.com/automotive-grade-linux/lava-mcp-toolkit/blob/main/docs/cra-compliance.md