Security

Vulnerability Disclosure

CraftedTrust's coordinated vulnerability disclosure policy for responsible AI agent ecosystem security research.

Effective: April 1, 2026

๐Ÿ›ก๏ธ About This Policy

CraftedTrust, operated by Cyber Craft Solutions LLC (craftedcybersolutions.com), is committed to improving the security of the AI agent ecosystem through responsible vulnerability research and coordinated disclosure.

๐Ÿ“‹ Scope

This policy covers vulnerabilities in:

Out of Scope: This policy does not cover vulnerabilities in the MCP specification itself, maintained by the Linux Foundation Agentic AI Foundation.

โฑ๏ธ Our Disclosure Timeline

When Cyber Craft Solutions discovers a vulnerability, we follow a 90-day coordinated disclosure process:

Day 0: Discovery & Notification Internal verification and proof of concept development. Maintainer notified via email with a detailed report including description, affected versions, proof of concept, suggested remediation, and CVSS severity rating.
Day 14: First Follow-up Follow-up notification if no response.
Day 30: Second Follow-up Alternative contact channels attempted (GitHub issues, security advisories, project maintainers).
Day 60: Third Follow-up Maintainer notified that public disclosure is planned for Day 90.
Day 90: Public Disclosure Advisory published at touchstone.craftedtrust.com/#advisories with full technical details, remediation guidance, and assigned CVE identifier.

Timeline Adjustments

๐Ÿ“Š Severity Rating

We use the Touchstone Security Rating (TSR) alongside CVSS v3.1 scoring. Advisories are categorized as:

Findings are mapped to CoSAI, OWASP Top 10 for Agentic Applications, EU AI Act Articles 9-15, NIST AI RMF, and AIUC-1.

๐Ÿ” CVE Assignment

Cyber Craft Solutions requests CVE identifiers for confirmed vulnerabilities through MITRE or the appropriate CNA. Advisories include CVE identifiers when assigned.

๐Ÿ”” Reporting a Vulnerability to Cyber Craft Solutions

If you discover a vulnerability in CraftedTrust's own products or services, please report it to [email protected].

What to Include

Our Response Timeline

โš–๏ธ Safe Harbor

CraftedTrust considers security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who:

๐Ÿ“ง Contact

Security Reports:
[email protected]

Advisories:
touchstone.craftedtrust.com/#advisories

RSS Feed:
touchstone.craftedtrust.com/api/v1/advisories/feed.xml

Cyber Craft Solutions LLC
Lancaster, PA
craftedcybersolutions.com