Skip to content

Security: agent-next/zagent

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please report security issues privately via GitHub Security Advisories ("Report a vulnerability" under the Security tab), not in public issues.

Include reproduction steps and the affected version (zagent --version). Reports are acknowledged within a few days.

Scope notes

zagent is a terminal client that drives your locally installed ZCode runtime under your own Coding Plan account. Credentials never leave your machine except to the endpoints you configure (api.z.ai / zcode.z.ai or your own).

There aren't any published security advisories