Adversary is a defensive QA tool — it tests your application's security boundaries in a sandbox.
If you find a security vulnerability in Adversary itself (not in an app it tests), please report it responsibly:
- Do not open a public issue.
- Email:
jasowills01@gmail.com(or open a private security advisory on GitHub:Security → Report a vulnerability). - Include: description, reproduction, impact, and suggested fix if known.
We aim to acknowledge within 48 hours and release a fix within 14 days for critical issues.
src/,skills/adversary/, CLI, sandbox, reporting engine- Example vulnerable app (
examples/vulnerable-app) is intentionally vulnerable — do not report its bugs as Adversary vulnerabilities.
We will not pursue legal action for good-faith research that follows coordinated disclosure and avoids privacy violations, DoS, or data exfiltration.
Adversary's own security checks are authorized, local/sandbox-only verification. It does not attack external systems. Do not use Adversary to test systems you are not authorized to test.