Security

Report a CrewScore vulnerability privately.

CrewScore is an offline static-analysis tool. Please report concrete security issues privately, especially ones involving prompt text, source URLs, analytics, the GitHub Action, publishing, or dependencies.

Report a vulnerability on GitHub

If GitHub is unavailable, email sarosh@pendoah.ai. Do not post secrets, customer prompts, or exploit payloads in a public issue.

What to include

Share the affected version or commit, a minimal synthetic reproduction, impact, and any suggested mitigation. We will acknowledge the report, assess scope, and coordinate a fix and disclosure timeline with the reporter.

Current project safeguards

Scope and limits

Reports may cover the Python package, GitHub Action, static site, generated browser engine, build and release automation, or published dependencies. A false positive or missing written control is normally a scoring-quality issue, not a security vulnerability.

CrewScore is not a security certification and does not prove an AI agent will follow written instructions. It checks whether guardrails are written down; runtime enforcement and adversarial testing remain separate.