Foreign Agricultural Service · Vulnerability Disclosure
Foreign Agricultural Service Vulnerability Disclosure
Vulnerability disclosure
Foreign Agricultural Service runs a coordinated vulnerability disclosure program on Bugcrowd.
AgricultureFederal GovernmentTradeOpen DataCommoditiesExportGovernment
Program: Bugcrowd
Disclosure Policy
Policy
Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-10'
method: searched
probe: true
source: https://bugcrowd.com/engagements/usda-vdp
note: >-
FAS itself publishes no security or disclosure page. What covers it is the parent
department's program: USDA runs a department-wide Vulnerability Disclosure Policy, operated
as a Bugcrowd engagement. fas.usda.gov and apps.fas.usda.gov are usda.gov subdomains, so the
agency inherits the department's policy the way a brand inherits its parent's — this is the
same different-domain justification the pipeline accepts for a parent brand, stated
explicitly rather than assumed.
program:
type: vulnerability-disclosure-policy
operator: Bugcrowd
managed_by: U.S. Department of Agriculture
bounty: false
bounty_note: 'a VDP, not a paid bug bounty — Bugcrowd classifies the engagement as "Vulnerability Disclosure"'
policy:
- https://www.usda.gov/vulnerability-disclosure-policy
- https://bugcrowd.com/engagements/usda-vdp
contact: []
contact_note: >-
Reports are submitted through the Bugcrowd engagement, not to an email address. No
security@ address is published for FAS or for USDA, and no /.well-known/security.txt is
served on any host — see well-known/foreign-agricultural-service-well-known.yml. The RFC
9116 discovery path a scanner would look for does not exist, which is why this program is
findable only by search.
evidence:
- source: https://bugcrowd.com/engagements/usda-vdp
kind: bug-bounty-platform-page
http_status: 200
fetched: '2026-09-10'
detail: >-
Live and public. Page title "Vulnerability Disclosure: United States Department of
Agriculture: Vulnerability Disclosure Program"; og:title "United States Department of
Agriculture: Vulnerability Disclosure Program | Bugcrowd"; og:description "Learn more
about U.S. Federal Government's Vulnerability Disclosure engagement powered by
Bugcrowd". Reached via a 301 from the older https://bugcrowd.com/usda-vdp path.
- source: https://www.usda.gov/vulnerability-disclosure-policy
kind: policy-page
http_status: 403
fetched: '2026-09-10'
detail: >-
NOT dead — an Akamai edge block on our crawler. The page returns the standard
"Access Denied" edgesuite body for any request from this client, as does every other
www.usda.gov path including the site root, while a browser-header request to the root
succeeded once in the same session. The URL is the one USDA itself publishes as its VDP
location. Recorded as live-but-unreadable rather than credited as read.
- source: /.well-known/security.txt on www.fas.usda.gov and www.usda.gov
kind: negative
http_status: 404
fetched: '2026-09-10'
detail: real origin 404 on both hosts — no RFC 9116 file
scope:
stated: USDA department-wide
fas_assets_verified: false
detail: >-
The Bugcrowd brief carrying the in-scope asset list returned 301 to our fetcher and was
not read, so it is NOT asserted here that fas.usda.gov or apps.fas.usda.gov appear on it
by name. What is asserted is what is verifiable: USDA operates a department-wide VDP, and
these are USDA hosts. A researcher should read the brief for the current asset list.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/foreign-agricultural-service-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.