Veil exists to keep secrets away from AI agents, so we treat any way to get a value out as a serious bug.
Please don't open a public issue. Report privately through GitHub security advisories.
Include what you did, what you expected, and what happened. A failing test
in the style of test/e2e/canary_test.go is the most useful thing you can
send. Never include real secret values.
We aim to acknowledge reports within 3 days and to ship a fix or a clear plan within 30 days. We'll credit you in the release notes unless you'd rather we didn't.
- Any way for an agent using Veil's MCP tools to obtain a secret value, including by encoding, splitting or reflecting it
- Sending a secret to a host, request part or command its rules don't allow
- Reading or changing the vault without the master key
- Secret values appearing in the audit log, error messages or
veiloutput - Using the web UI to reveal a value or loosen a rule without Touch ID, or reaching it from another website
- Reading the master key on macOS without the Keychain asking the user
Gaps already listed in docs/threat-model.md are known. New ways to exploit them, or ideas to close them, are still welcome.
Until 1.0, only the latest release gets security fixes.