AgiBot · Vulnerability Disclosure

Agibot Vulnerability Disclosure

Vulnerability disclosure

AgiBot publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyRoboticsHumanoid RobotsEmbodied AIArtificial IntelligenceManufacturingHardwareMiddlewareROS 2gRPCProtocol BuffersSimulationMachine LearningOpen SourceModel Context ProtocolAgentic CommerceChina
Program:

Disclosure Policy

Security Contact

Contact
emailsecurity@agibot.com
Contact
methodemail
Contact
urlmailto:security@agibot.com

Source

Vulnerability Disclosure

agibot-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-06'
method: searched
source: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf
docs: https://www.agibot.com/filepage/282.html
notes: AgiBot (Zhiyuan Robotics) publishes a full vulnerability disclosure policy — but as a PDF linked
  from the Document Center, not as an RFC 9116 /.well-known/security.txt. Every AgiBot host returns 404
  for security.txt, so the policy is invisible to automated discovery. Publishing a security.txt pointing
  at this PDF and at security@agibot.com would make the existing programme machine-discoverable at no
  cost.
x-evidence:
  fetched: '2026-08-06'
  url: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf
  http_status: 200
  content_type: application/pdf
  bytes: 47903
program:
  published: true
  type: vulnerability disclosure policy (VDP)
  bug_bounty: false
  monetary_rewards: false
  reward_note: The policy states explicitly that AgiBot does not offer monetary rewards for vulnerability
    disclosures.
  platform: null
  safe_harbor: not stated
contact:
  email: security@agibot.com
  method: email
  url: mailto:security@agibot.com
policy_url: https://www.agibot.com/public/uploads/file/Publication%20of%20Vulnerability%20Disclosure%20Policy.pdf
report_requirements:
  mandatory:
  - Title of vulnerability
  - Description of vulnerability with summary, supporting files and possible mitigations
  - Impact — what an attacker could do
  - Steps to reproduce as a benign, non-destructive proof of concept
  optional:
  - Asset (web address, IP address, product or service name) where the vulnerability can be observed
  - Weakness (CWE)
  - Severity (CVSS v3.0)
  - Reporter name and email address
response_targets:
  acknowledgement: 5 working days
  triage: 10 working days
  status_enquiries: no more than once every 14 days
  remediation: prioritised by impact, severity and exploit complexity; reporter notified on remediation
    and may be invited to confirm the fix
coordinated_disclosure:
  permitted: true
  note: Public disclosure requests are welcomed once the vulnerability is resolved, and must be coordinated
    with AgiBot so guidance to affected users is unified.
prohibited_activity:
- Breaking any applicable law or regulation
- Accessing unnecessary, excessive or significant amounts of data
- Modifying data in the Organization’s systems or services
- Using high-intensity invasive or destructive scanning tools
- Attempting or reporting any form of denial of service
- Disrupting the Organization’s services or systems
security_txt:
  present: false
  probed:
  - https://www.agibot.com/.well-known/security.txt
  - https://x2-aimdk.agibot.com/.well-known/security.txt
  - https://www.agibot.com.cn/.well-known/security.txt
  - https://store.agibot.com/.well-known/security.txt
  status: 404