Merit Systems · Vulnerability Disclosure

Merit Systems Vulnerability Disclosure

Vulnerability disclosure

Merit Systems publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyAgentic CommercePaymentsx402MicropaymentsModel Context ProtocolStablecoinsAPI DiscoveryOpen SourceDeveloper Tools
Program:

Disclosure Policy

Policy

Security Contact

Contact
https://github.com/Merit-Systems/agentcash-router/security/advisories/new

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-20'
method: searched
probe: true
source: https://github.com/merit-systems/agentcash-router/blob/main/SECURITY.md
policy:
  - https://github.com/merit-systems/agentcash-router/blob/main/SECURITY.md
contact:
  - https://github.com/Merit-Systems/agentcash-router/security/advisories/new
channel: GitHub Security Advisories (private "Report a vulnerability")
acknowledgement_sla: 3 business days
scope: >-
  Payment verification and settlement (x402, MPP) and wallet-based
  authentication (SIWX) paths in @agentcash/router — e.g. payment bypass,
  settlement without verification, auth bypass, replay.
public_issue_reports: disallowed
credit: Reporters credited in the fix release unless they prefer otherwise.
evidence:
  - source: https://github.com/merit-systems/agentcash-router/blob/main/SECURITY.md
    kind: security-policy
notes: >-
  No /.well-known/security.txt found on merit.systems, agentcash.dev,
  echo.merit.systems, or x402scan.com (all 404 as of 2026-07-20). Disclosure is
  handled through the repository Security Policy and GitHub Security Advisories.