Code of Conduct
The Agent Interoperability Protocol project is committed to a professional, safe, and evidence-based technical community. Participation is conditioned on respect for other contributors and for the users affected by protocol, security, and deployment decisions.
Expected Behavior
Participants are expected to:
- discuss technical claims with specific reasoning, reproducible evidence, and respect for uncertainty;
- criticize designs and code without attacking the person who proposed them;
- disclose relevant limitations, conflicts of interest, and security impact;
- respect privacy, credentials, customer data, and embargoed vulnerabilities;
- accept correction and update claims when stronger evidence becomes available;
- make space for contributors with different backgrounds and levels of familiarity with the codebase;
- follow maintainer directions during incident response and moderated review.
Unacceptable Behavior
The following behavior is not acceptable:
- harassment, threats, intimidation, stalking, or discriminatory language;
- personal insults, sexualized content, or unwelcome personal attention;
- publishing another person’s private information without explicit permission;
- knowingly false technical or qualification claims;
- disclosing credentials, customer data, private vulnerability details, or protected deployment information;
- disrupting reviews, issue tracking, releases, or community communication;
- retaliating against a person who reports a concern in good faith.
Scope
This policy applies in repository discussions, reviews, issue trackers, project-operated communication channels, release and qualification activities, and public situations where a participant represents the project.
Technical disagreement is expected. This policy does not prohibit firm review, rejection of unsupported claims, or restrictions needed to protect protocol integrity and users.
Reporting
Report conduct concerns privately to the project maintainers through the repository host’s private contact or security-reporting channel. Do not place sensitive personal information in a public issue.
Include the location, time, people involved, relevant context, and any records needed to understand the incident. Reports will be shared only with people who need the information to review and resolve the concern. Deliberately false or retaliatory reports are themselves a violation; a good-faith report that is not substantiated is not.
Security vulnerabilities must follow SECURITY.md instead of the conduct process.
Enforcement
Maintainers may take action proportionate to the behavior and its impact, including:
- a private correction or request to stop;
- a formal warning with conditions for continued participation;
- temporary restriction from discussions, reviews, or project spaces;
- permanent removal from project spaces;
- escalation to the repository host or relevant organization when required for safety or legal compliance.
Maintainers involved in a report must recuse themselves when they cannot review it impartially. Enforcement decisions should identify the violated rule, the required corrective action, and any duration or appeal path that applies.
Maintainer Responsibility
Maintainers are responsible for clarifying and enforcing this policy consistently. They may remove, edit, or reject contributions and communication that violate it. Private report information must not be used for unrelated purposes.