AmbitLive demoGuideFAQReferenceJevAll docsGitHub

Security

Reporting

Report vulnerabilities privately through GitHub: Security → Report a vulnerability. Private reporting is enabled on this repository. Please do not open a public issue for anything exploitable.

Ambit is a personal project, not a staffed one — expect a first response in days rather than hours.

What is worth reporting

Ambit reads your agent configuration and, through the visualizer, writes back to it. Four invariants hold that surface, and a break in any of the four is a vulnerability. AGENTS.md says where each of the four is enforced in code.

Also in scope: anything that causes the engine to execute content from a scanned configuration or infrastructure manifest.

What is not

Where your data is

The graph is a local SQLite file whose path ambit where prints, and it describes your machines, your credentials-adjacent tooling, and your network reach. ambit graph and ambit status describe your machine too, so redact before pasting either into a report; the FAQ lists the commands that can move data and what each one sends.