Skip to content

Security: ag2ai/ag2-assistant

Security

.github/SECURITY.md

Security Policy

Security and stability matter for AG2 Assistant. Because the assistant can run code, read files, and connect to external services, we take reports seriously.

Supported versions

The latest release is actively supported. We encourage you to keep your installation up to date so you benefit from the latest fixes and security updates.

Reporting a vulnerability

If you suspect a security issue, even if you are uncertain, please report it promptly — but do not open a public issue.

To report privately, use the Security tab of the repository and click "Report a vulnerability", or email support@ag2.ai.

Please include enough detail to reproduce the issue. A minimal, reproducible example greatly speeds up triage.

Response and disclosure timeline

  • Acknowledgement: within 3 business days of receiving your report.
  • Fix or mitigation: within 90 days for confirmed vulnerabilities, coordinated with the reporter where appropriate.

If we can't meet these targets for a specific issue, we'll explain why and share a revised timeline.

Safe harbor for security researchers

We support good-faith security research and will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
  • Only interact with accounts and data they own or have explicit permission to access.
  • Report vulnerabilities promptly via the channels above and do not disclose them publicly until we've had a reasonable opportunity to remediate.

Activity consistent with this policy is considered authorized, and we'll work with you to understand and resolve issues quickly.

Thanks for helping keep AG2 Assistant and its users safe.

There aren't any published security advisories