generated: '2026-09-19' method: searched probe: true policy: - https://github.com/RodCor/kimetsu.dev/blob/main/SECURITY.md - https://github.com/RodCor/sidequest-commons/blob/main/SECURITY.md contact: - GitHub private vulnerability reporting (Security -> Report a vulnerability) on RodCor/kimetsu.dev and RodCor/sidequest-commons channel: github-security-advisories bug_bounty: null security_txt: null evidence: - source: https://raw.githubusercontent.com/RodCor/kimetsu.dev/main/SECURITY.md kind: SECURITY.md http_status: 200 keywords: - Report vulnerabilities privately through GitHub's security advisory flow - Agent gateway threat model - rejects requests carrying Authorization, Cookie, or Proxy-Authorization - source: https://raw.githubusercontent.com/RodCor/sidequest-commons/main/SECURITY.md kind: SECURITY.md http_status: 200 keywords: - Use the repository's Security -> Report a vulnerability flow - Credential posture - Supported surface - Maintainers may pause proposal intake or daily selection while investigating - source: https://github.com/RodCor/sidequest-commons/blob/main/THREAT_MODEL.md kind: threat model note: Companion threat model (rendered at https://rodcor.github.io/sidequest-commons/security/ — "Threat model v1", fail-closed, no stored participant credentials, secretless fork CI). - source: https://raw.githubusercontent.com/RodCor/kimetsu/main/SECURITY.md kind: SECURITY.md http_status: 404 note: The main kimetsu product repo has no SECURITY.md; its contributing page says "Report security issues privately rather than in a public issue" and CI runs cargo-audit (RUSTSEC) and cargo-deny. probe_result: script: probe-security-programs.py (2026-09-19) -> vdp=none trust=none note: 'The probe checks /.well-known/security.txt and /security* paths on the domain, all of which 404 (kimetsu.dev and agents.kimetsu.dev). The disclosure policy is published in the GitHub repositories that build the site and the gateway, which the probe does not read; recorded here by hand from the fetched files.' scope: in_scope: - kimetsu.dev website and agents.kimetsu.dev gateway (kimetsu.dev repo SECURITY.md) - Sidequest Commons website, policy compiler, daily selector, generated project boundary, workflow configuration on main (sidequest-commons SECURITY.md) response: Maintainers may pause proposal intake or daily selection while investigating; a confirmed trust-boundary bypass blocks releases until the boundary is restored and a regression test exists.