Skip to content

Trust & security

Security

Updated: 24 July 2026 · Report privately · Do not open public issues for payment or key findings

Standing rule: no publicly reachable admin surface without server-side auth. Sealed skill payloads are not in the public catalog. Confirmed unlocks are verified on-chain.

1. Payment security (x402)

2. Sealed packs & catalog

3. Machine surfaces

4. What we protect

5. What you must protect

6. Responsible disclosure

Found a vulnerability in payment verification, auth, sealed-pack delivery, or admin exposure?

Machine-readable pointer: /security.txt · /.well-known/security.txt

7. Verify us yourself

8. Related policies

Privacy Policy · Terms of Service · Learn: Security and trust · Trust hub

API health Proof ledger Marketplace