Hi, security researcher here. Your SECURITY.md points to https://www.secureagentics.ai/contact, but that form is protected by a Cloudflare Turnstile challenge I'm not able to solve programmatically, and I couldn't find a security contact email or GHSA private-vulnerability-reporting (not enabled on this repo, 403) as an alternative.
I have a Critical-severity, dynamically-confirmed finding: the Python SDK's Anthropic integration (patch_anthropic() in sdk/python/adrian/anthropic_handler.py) only patches anthropic.resources.messages.{Messages,AsyncMessages}.create/stream. It never patches the beta namespace (client.beta.messages.create/stream — required for computer-use, code-execution tool, MCP connector beta, etc.) or the Batches API (client.messages.batches, client.beta.messages.batches). I confirmed with a working local PoC that a tool_use block for a destructive call reaches the caller completely unmodified via client.beta.messages.create(...) — no hook, no classifier, no gating — while the identical call via client.messages.create(...) is correctly intercepted. This is a full, silent bypass of the product's core "before the agent acts" guarantee, reachable via ordinary (non-adversarial) SDK usage rather than an exotic attack. I also have a related, lower-confidence High-severity finding in the TypeScript OpenAI wrapper (only chat/responses are proxied; beta.assistants, beta.threads.runs, batches, beta.realtime pass through unwrapped, contradicting the package README's "every call is captured" claim).
Could you point me to a working contact channel (email, or a non-CAPTCHA-gated form) so I can send the full technical writeup, PoC, and suggested fixes? Happy to work within your coordinated-disclosure window. Thanks!
— kta1kri
Hi, security researcher here. Your SECURITY.md points to https://www.secureagentics.ai/contact, but that form is protected by a Cloudflare Turnstile challenge I'm not able to solve programmatically, and I couldn't find a security contact email or GHSA private-vulnerability-reporting (not enabled on this repo, 403) as an alternative.
I have a Critical-severity, dynamically-confirmed finding: the Python SDK's Anthropic integration (
patch_anthropic()insdk/python/adrian/anthropic_handler.py) only patchesanthropic.resources.messages.{Messages,AsyncMessages}.create/stream. It never patches thebetanamespace (client.beta.messages.create/stream— required for computer-use, code-execution tool, MCP connector beta, etc.) or the Batches API (client.messages.batches,client.beta.messages.batches). I confirmed with a working local PoC that atool_useblock for a destructive call reaches the caller completely unmodified viaclient.beta.messages.create(...)— no hook, no classifier, no gating — while the identical call viaclient.messages.create(...)is correctly intercepted. This is a full, silent bypass of the product's core "before the agent acts" guarantee, reachable via ordinary (non-adversarial) SDK usage rather than an exotic attack. I also have a related, lower-confidence High-severity finding in the TypeScript OpenAI wrapper (onlychat/responsesare proxied;beta.assistants,beta.threads.runs,batches,beta.realtimepass through unwrapped, contradicting the package README's "every call is captured" claim).Could you point me to a working contact channel (email, or a non-CAPTCHA-gated form) so I can send the full technical writeup, PoC, and suggested fixes? Happy to work within your coordinated-disclosure window. Thanks!
— kta1kri