AgentMesh · Vulnerability Disclosure

Agentmesh Link Vulnerability Disclosure

Vulnerability disclosure

AgentMesh runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AI AgentsAgent NetworksAgent DiscoveryA2AMCPKnowledge SharingMulti-Agent OrchestrationTask RoutingMessagingArtificial IntelligenceAgent-NativeDeveloper Tools
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
general_contactOne address on /terms and /privacy (Cloudflare email-protected; not reproduced here). Not designated for security.
Contact
security_emailnot-published

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://github.com/lugdwei/AgentMesh-Public/blob/main/SECURITY.md
corroboration: probe-security-programs.py (vdp=none trust=none — it reads security.txt and site paths, not GitHub) and live probes 2026-09-19
checked: '2026-09-19'
summary: >-
  AgentMesh publishes a short security policy in its public GitHub repository and nothing on its
  own host: no RFC 9116 security.txt, no /security or /trust page, no bug bounty, no safe-harbour
  statement, no response-time commitment. The policy's substance is one instruction — report
  privately through GitHub's private vulnerability reporting / Security Advisory mechanism for the
  repository "when available", and never post exploit details or credentials in a public issue.
  That is a real, published disclosure channel, so a Security pointer is emitted; a reader should
  know it is the thinnest form the check accepts and that it lives on GitHub rather than on the
  service.
published: true
policy:
  url: https://github.com/lugdwei/AgentMesh-Public/blob/main/SECURITY.md
  raw: https://raw.githubusercontent.com/lugdwei/AgentMesh-Public/main/SECURITY.md
  status: 200
  title: Security Policy
  added: '2026-09-06 (commit "docs: add public security policy")'
  reporting_channel: GitHub private vulnerability reporting / Security Advisory on lugdwei/AgentMesh-Public
  reporting_verbatim: >-
    "Do not publish exploitable vulnerability details or credentials in a public issue. Use
    GitHub's private vulnerability reporting / Security Advisory mechanism for this repository when
    available. Include enough information to reproduce the issue without including live secrets or
    personal data."
  scope_verbatim: >-
    "This repository is the public developer portal and documentation surface. The AgentMesh
    production backend and its private source history are intentionally not published here."
  scope_note: >-
    The policy scopes ITSELF to the documentation repository, and the production service is
    explicitly out of that repository. Whether a report about app.agentmesh.link (the live API) is
    in scope is not stated; the GitHub advisory channel is nonetheless the only reporting path
    published anywhere.
  private_reporting_enabled: unverified
  private_reporting_note: >-
    Whether GitHub private vulnerability reporting is actually switched on for the repository is
    not observable anonymously ("when available" in the policy suggests it may not be). Not
    claimed.
  response_time: not-published
  safe_harbour: false
  in_scope_out_of_scope: not-published
  secrets_hygiene_rule: 'Never submit API keys, agent credentials, access tokens, Stripe secrets, webhook signing secrets, private keys, passwords, environment files or database dumps.'
contact:
  security_email: not-published
  general_contact: 'One address on /terms and /privacy (Cloudflare email-protected; not reproduced here). Not designated for security.'
rfc9116:
  served: false
  probes:
    - {url: 'https://app.agentmesh.link/.well-known/security.txt', status: 404}
    - {url: 'https://agentmesh.link/.well-known/security.txt', status: 0, error: 'Could not resolve host'}
  fix: 'Serving a security.txt with Contact: the GitHub advisory URL and a Policy: line pointing at SECURITY.md is a one-file change that would make the channel discoverable from the service itself.'
site_pages:
  probes:
    - {url: 'https://app.agentmesh.link/security', status: 404}
    - {url: 'https://app.agentmesh.link/trust', status: 404}
    - {url: 'https://app.agentmesh.link/.well-known/security.txt', status: 404}
bug_bounty:
  published: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  result: none found
  intigriti_note: >-
    https://app.intigriti.com/programs/agentmesh answers 200, but so does a negative-control
    program path (zzz-no-such-program-7f3ab91c) with a byte-identical 251,569-byte SPA shell, so
    the 200 is the app shell and not a program. Recorded so a later round does not credit it. Any
    real Intigriti/HackerOne program named "agentmesh" would also need to be tied to THIS provider —
    three unrelated products share the name.
trust_center:
  present: false
  probes: [{url: 'https://app.agentmesh.link/trust', status: 404}]
  note: 'No trust-center artifact is written and no TrustCenter or Compliance pointer is emitted.'
security_headers_observed:
  host: https://app.agentmesh.link
  hsts: absent
  content_security_policy: absent
  x_frame_options: absent
  x_content_type_options: absent
  note: 'From a HEAD of the homepage on 2026-09-19; only Cloudflare edge headers present. TLS 1.3, cert to 2026-12-04 (see agentmesh-link-domain-security.yml). DNSSEC, CAA, SPF and DMARC are all absent on agentmesh.link.'
pointer_basis: >-
  `Security` (security_disclosure) is emitted on the strength of the published SECURITY.md with a
  named private reporting channel. `SecurityTxt`, `TrustCenter` and `Compliance` are NOT emitted.
cross_links:
  domain_security: security/agentmesh-link-domain-security.yml
  well_known: well-known/agentmesh-link-well-known.yml
  regulatory: regulatory/agentmesh-link-regulatory-posture.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agentmesh-link-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.