M
Mago Foundation

Public Operating Layer

The commitments, boundaries, and operational transparency data required to trust Mago's agent behavioral attestation.

Security and Disclosure

We welcome responsible vulnerability disclosure. By submitting reports through our official channels, security researchers are protected by our Safe Harbor policy.

  • Response Times: Initial acknowledgement within 48 hours. Remediation timelines depend on severity (Critical: < 7 days).
  • CVE Policy: Mago acts as a CNA for components within `magofoundation/*`.
  • Advisory Archive: All historical vulnerabilities are logged in the Public Advisory Repository.

Product Boundaries & Trust

Mago establishes cryptographically verifiable identity and behavior attestation for agent skills. It does not guarantee a skill is free of bugs, nor does it override an agent's host OS sandboxing.

In Scope (Claims)

  • - Cryptographic skill authorship (Ed25519)
  • - ABC Trace bounds execution limits
  • - Transparency log immutability

Out of Scope (Non-claims)

  • - Memory safety of underlying python tools
  • - Agent hallucination mitigation
  • - Enterprise IAM authentication

Operational Trust Material

Access the raw cryptographic materials required to verify Mago's infrastructure state independently.

Resource Status / Link
Trust-root Metadata (v1) trust-root.json
Transparency Log Checkpoints rekor.magofoundation.dev
Verifier CLI Release Signatures cosign.pub
Revocation Lookups (CRL) crl.magofoundation.dev

Governance and Community

Mago operates under open-source governance. All components are licensed under the MIT License unless stated otherwise.

Third-Party Evaluators

We welcome red-team submissions to test our Agent Behavioral Checksums. Please review our AUP prior to submitting adversarial payloads to the public registry.

Privacy & Evidence-Handling

Prior to collecting external submissions for evaluation, Mago adheres to strict evidence-handling guidelines to protect researcher data and avoid cross-contamination.

Evidence Collection: Telemetry is strictly opt-in. Submitted skill traces are scrubbed of PII locally before uploading.

Retention & Deletion: Evaluation traces are stored for 90 days. Raw execution dumps are deleted immediately post-validation.

Processing Location: All infrastructure runs in EU-central zones with restricted access controls.

Privacy Contact: privacy@magofoundation.dev