> For an index of all Botscent documentation, see https://botscent.nibnalin.me/llms.txt.

# Security and contributing

How to report a vulnerability, what counts as one, how to contribute, and the license.

Botscent is open source under the MIT license. This page tells you how to report a problem and how to add an agent.

## Report a vulnerability

Report a vulnerability in private, not in a public issue. Use the **Security → Report a vulnerability** page of the [repository](https://github.com/nalinbhardwaj/botscent). Include the version, the runtime, and a request, page or input that shows the problem. You get an answer within 3 working days.

## What counts as a vulnerability

A detection library gets reports that are not vulnerabilities. This is the line:

* **A vulnerability:** a verifier that accepts a Web Bot Auth signature it must reject. `isVerified` that returns true for anything other than the request's own verified evidence. Anything that lets page content change the server half's verdict. Anything that makes the library throw into your page or your application.
* **Handled like a vulnerability:** a person reported as an agent, anywhere except inside an agent product's own browser. This is the most serious bug the library can have. Report it in private or in public, whichever is faster for you.
* **Not a vulnerability:** an agent that evades detection. That is a coverage report. Open an ordinary issue.
* **Out of scope:** access control on an unverified name, an `agent_name` or a reason, without `isVerified`. Names and declarations are claims. See [The trust model](/docs/trust-model).

The latest minor release receives fixes. Each release bundles the signers' keys, so an upgrade also keeps signature checks current. See [Versions and stability](/docs/versions).

## Report a missed agent

Open an issue with the agent's name and how you ran it. Add what the agent sends or shows, for example its user agent or the debug output. To get the debug output, add `data-debug` to the script tag, or start the server with `BOTSCENT_DEBUG=1`.

## Contribute

Issues and pull requests are welcome. The repository's `AGENTS.md` lists the commands and the rules, for people and agents alike. In short:

* The contract in `spec/` is the specification.
* The TypeScript and Python halves must give the same verdicts on the test vectors in `vectors/`.
* `registry/*.json` is the one source of data. Generated files are never edited by hand.
* A change to any verdict is a minor release. Add a changeset with `npx changeset`.

To add an agent, add its name to `registry/names.json`. Then add the evidence that identifies it: a user-agent token, a Web Bot Auth signer and its keys, or a page declaration. The repository's `CONTRIBUTING.md` gives the steps.

## Sign off your commits

Contributions are accepted under the [Developer Certificate of Origin](https://developercert.org/), not a contributor license agreement. Sign off every commit:

```sh title="Terminal"
git commit -s
```

The sign-off certifies that you wrote the change, or have the right to submit it under the MIT license.

## License

Botscent is under the MIT license. You can use it in commercial and closed-source projects. Keep the copyright notice and the license text with copies of the code.

## Related

* [The trust model](/docs/trust-model): which verdicts are fit for access.
* [Privacy](/docs/privacy): every probe and every header the library reads.
* [Versions and stability](/docs/versions): what each kind of release can change.
