Korso · Vulnerability Disclosure

Korso Vulnerability Disclosure

Vulnerability disclosure

Korso publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceAgentsMCPDeveloper ToolsOpen-SourceAgent CoordinationY Combinator
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@korsoai.com
Contact
https://github.com/Korso-AI/shepherd/security/advisories/new

Source

Vulnerability Disclosure

korso-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://github.com/Korso-AI/Shepherd/blob/main/SECURITY.md
note: >-
  The automated probe reported a hit on https://korsoai.com/vulnerability-disclosure, but that path is
  the korsoai.com single-page-app catch-all, which returns HTTP 200 with the "Sign in - Korso Console"
  shell for ANY unknown path. That was a false positive and has been replaced with the real, verified
  policy published as SECURITY.md in the Shepherd repository.
policy:
- https://github.com/Korso-AI/Shepherd/blob/main/SECURITY.md
contact:
- security@korsoai.com
- https://github.com/Korso-AI/shepherd/security/advisories/new
preferred_channel: GitHub Security Advisories
bug_bounty: false
public_disclosure_program: null
response_targets:
  acknowledgement: 3 business days
  initial_assessment_and_severity: 7 business days
  remediation: coordinated disclosure timeline agreed with the reporter
scope:
- packages/hub
- packages/mcp-server
- packages/shared
- packages/ui
- Korso-hosted platform front-end/BFF and auth layer (separate non-public repo; reports accepted through
  the same channels)
supported_versions: >-
  Security fixes are applied to the latest release on the main branch. Users are advised to run the most
  recent published version of @korso/shepherd and @korso/shepherd-ui.
credits_reporters: true
evidence:
- source: https://raw.githubusercontent.com/Korso-AI/Shepherd/main/SECURITY.md
  kind: security policy
  status: 200
  keywords:
  - report a vulnerability
  - do not open a public github issue
  - security@korsoai.com
  - github security advisories
- source: https://korsoai.com/.well-known/security.txt
  kind: security.txt
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/korso-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.