Use a private GitHub Security Advisory in the agentx-server Security tab to report a vulnerability. Include the affected version, reproduction steps, impact, and a suggested mitigation. Do not publish credentials or exploit details in a public Issue.
Hosted deployments should use OIDC or a managed token strategy and TLS. Do not place API tokens or signing keys in a Manifest or Artifact.