SECURITY

Report a security issue

If you find a problem with agent-kg.ai — a key that does not verify, a door that answers wrong, a receipt that will not resolve, a header that lies — tell the office.

  • Machine-readable contact and policy: /.well-known/security.txt
  • Scope: agent-kg.ai and its twins (.com, .io, .org), the machine kit, /api and /x402, the authorization server.
  • Out of scope: the operating companies' estates, which have their own security pages, and any third-party rail (Cloudflare, Coinbase, Formspree).
  • What to send: the URL, the request you made, what came back, and what you expected. Signed reports are welcome; the office keyring is at /.well-known/jwks.json if you want to encrypt to it.
  • What the office does: acknowledges within five business days, fixes on the office's own clock, and credits you on this page if you want credit.

No bounty. Good-faith research within scope will not be met with legal action.