The agreement prohibits uploading, hosting, or transmitting malicious code, and also prohibits using GitHub infrastructure as part of any system designed to deliver or amplify cyberattacks, including command-and-control infrastructure.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision prohibits not only direct malware hosting but also the use of GitHub repositories or infrastructure as attack support systems, which has particular relevance for security researchers whose dual-use tools or proof-of-concept exploit code may be assessed under this restriction.
Interpretive note: The scope of 'part of a system designed to deliver or amplify cyberattacks' is not precisely defined in the master AUP and requires reference to the subsidiary active malware and exploits sub-policy for further interpretive guidance, particularly for dual-use security tools.
Under this clause, hosting malicious code or using GitHub infrastructure to support cyberattack delivery or command-and-control operations is prohibited, and such content or accounts are subject to removal or suspension. Security researchers should note that dual-use tools and proof-of-concept exploit code may require evaluation against this provision and GitHub's specific security research policy.
How other platforms handle this
You may not display any personal contact, banking, or peer-to-peer payment information, whether in relation to you or any other person (for example, names, home addresses or postcodes, telephone numbers, email addresses, URLs, credit/debit card...)
Bypass or ignore instructions contained in our robots.txt file that controls automated access to portions of our Services;
Send content created in Mailchimp through another service.
"You may not upload, post, host, or transmit any content that: contains malicious code, or is part of a system designed to deliver or amplify cyberattacks, including by providing infrastructure for hosting malicious content or command-and-control for attacks.Excerpt from GitHub's Acceptable Use Policies
1) REGULATORY LANDSCAPE: This provision engages the Computer Fraud and Abuse Act (CFAA), which prohibits unauthorized access to computer systems and the distribution of code used to damage protected computers.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision prohibits not only direct malware hosting but also the use of GitHub repositories or infrastructure as attack support systems, which has particular relevance for security researchers whose dual-use tools or proof-of-concept exploit code may be assessed under this restriction.
Under this clause, hosting malicious code or using GitHub infrastructure to support cyberattack delivery or command-and-control operations is prohibited, and such content or accounts are subject to removal or suspension. Security researchers should note that dual-use tools and proof-of-concept exploit code may require evaluation against this provision and GitHub's specific security research policy.
ConductAtlas has identified this type of provision across 282 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.