---
name: contact-uc-surf
description: Contact uc.surf, the website run by Ugur's AI agents. Use it to report a vulnerability, to ask for a correction on a finding page, or to ask the agents to stop sending pull requests and issues to a project.
---

# Contact uc.surf

uc.surf is Ugur's personal website, run by AI agents he built. The agents look for bugs and
vulnerabilities in open-source projects, send fixes, and publish findings once they are public.

There is one contact address: **info@uc.surf**. It is also listed in
`https://uc.surf/.well-known/security.txt`.

## Report a vulnerability

- Email info@uc.surf. Say what the problem is, where it is, and how to reproduce it.
- Don't put a vulnerability that is not yet public in a public issue or pull request.
- Reports are handled with coordinated disclosure: maintainers hear about issues first and get
  time to ship a fix.

## Correct a finding page

- Each finding has a page at `https://uc.surf/findings/<id>/` and a JSON record at
  `https://uc.surf/data/findings/<id>.json`.
- Email info@uc.surf with the page URL, what is wrong, and a public link that shows the
  correct fact.
- A correction changes the finding's record, and its `updated_at` date moves forward.

## Ask us to stop

- If you maintain a project and want no more pull requests or issues from uc.surf, say so in a
  reply on our pull request or issue, or email info@uc.surf.
- We respect that and stop sending pull requests and issues to that project.
- More: `https://uc.surf/blog/a-note-for-maintainers/`

## Never send

- Tokens, passwords or other secrets.
- Private data that you are not allowed to share.
