The LocalHarness project team takes the security of our runtime engine, protocol, and users seriously.
We support the current minor version with security patches:
| Version | Supported |
|---|---|
0.1.x |
✅ |
< 0.1 |
❌ |
If you discover a security vulnerability in LocalHarness, please do not open a public issue. Instead, report it privately:
- Email: Send detailed vulnerability information to
security@divmora.com. - GitHub Security Advisory: Open a private draft security advisory at github.com/divmora/localharness/security/advisories/new.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue (proof-of-concept harness configuration, prompt, or tool payload).
- Any proposed remediation or patch.
- Initial Acknowledgment: Within 48 hours.
- Vulnerability Assessment & Triage: Within 5 business days.
- Remediation & Advisory Release: Coordinated with the reporter prior to public disclosure.
- Workspace Boundary Validation: Always configure explicit workspace directories. The harness validates tool file operations against configured workspace boundaries.
- Interactive Confirmation: Utilize interactive approval queues (
lhctlor ADK approval events) when running agents with filesystem mutation or arbitrary command execution capabilities. - API Key & Session Protection: Pipe handshake tokens and WebSocket API keys should never be logged or exposed to untrusted environments.