generated: '2026-09-19' method: searched source: https://github.com/luthersystems/insideout-agent-skills/blob/main/SECURITY.md also: - https://github.com/luthersystems/substrate-agent-skills/blob/main/SECURITY.md - https://github.com/luthersystems/agent-skills/blob/main/SECURITY.md - https://github.com/luthersystems/insideout-claude-code/blob/main/SECURITY.md - https://github.com/luthersystems/insideout-power/blob/main/SECURITY.md description: >- Luther Systems publishes a vulnerability-reporting channel — security@luthersystems.com — in the SECURITY.md of each public agent-product repository, and the InsideOut MCP server exposes a submit_feedback tool that accepts category "security". probe-security-programs.py found nothing on the web hosts (no /.well-known/security.txt on any of eight hosts, no HackerOne/Bugcrowd/Intigriti program, no disclosure page on luthersystems.com), so this record is GitHub-published policy, not a security.txt or bug bounty. No safe-harbour language, response SLA or reward is stated. The InsideOut SECURITY.md also documents the data flow and trust boundaries of the hosted MCP server (what is and is not sent; credentials never transit the agent) and notes the repo runs a Snyk agent scan workflow. contact: mailto:security@luthersystems.com policy_url: https://github.com/luthersystems/insideout-agent-skills/blob/main/SECURITY.md channels: - type: email value: security@luthersystems.com - type: mcp-tool value: submit_feedback (category "security") on https://app.luthersystems.com/v1/insideout-mcp bug_bounty: null safe_harbor: false security_txt: false hall_of_fame: null x-evidence: - {url: 'https://raw.githubusercontent.com/luthersystems/insideout-agent-skills/main/SECURITY.md', status: 200} - {url: 'https://raw.githubusercontent.com/luthersystems/substrate-agent-skills/HEAD/SECURITY.md', status: 200} - {url: 'https://www.luthersystems.com/.well-known/security.txt', status: 404} - {url: 'https://agentsearch.luthersystems.com/.well-known/security.txt', status: 404}