Skip to content

Security: Larry7/ClawNexus

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x
< 0.2

Reporting a Vulnerability

If you discover a security vulnerability in ClawNexus, please report it responsibly.

Email: alan@silverstream.tech

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Any relevant logs or screenshots

Response Timeline

  • Acknowledgement: within 48 hours
  • Initial assessment: within 5 business days
  • Fix or mitigation: as soon as reasonably possible, depending on severity

Scope

This policy covers the following packages:

  • clawnexus (daemon + CLI)
  • clawnexus-skill (OpenClaw Skill)
  • @clawnexus/sdk (SDK)

Disclosure

We follow coordinated disclosure. Please do not open public issues for security vulnerabilities. We will credit reporters in the release notes unless anonymity is requested.

There aren’t any published security advisories