Skip to content

Security: anwarj03/LLMRed

Security

SECURITY.md

Security Policy

Authorized use

LLMRed is intended only for systems you own or are explicitly authorized to assess. Obtain written permission, define the target scope, agree on traffic and time limits, and identify an emergency contact before running active tests.

Potentially disruptive and state-changing checks are disabled or separately gated. Do not weaken those safeguards when testing production systems.

Reporting a vulnerability

Please report vulnerabilities in LLMRed privately through this repository's GitHub Security Advisories feature. Do not open a public issue containing an exploit, credential, customer data, assessment evidence, or target details.

Include the affected version or commit, reproduction steps, expected impact, and any suggested mitigation. Use synthetic data wherever possible.

Sensitive assessment data

Generated reports, API keys, local databases, forensic bundles, audit logs, target-specific configurations, and completed NIST evidence profiles must not be committed. The repository ignore rules cover their standard locations, but each operator remains responsible for reviewing staged changes before publishing.

There aren't any published security advisories