Security fixes are generally applied to the latest version of the project. Support for older releases may be limited.
Please do not publish sensitive security details in a public GitHub issue.
Report security vulnerabilities privately through the repository owner's available GitHub security/contact mechanism.
Include:
- a short description
- affected file, endpoint, or feature
- steps to reproduce
- expected behavior
- actual behavior
- potential impact
- a safe proof of concept, when necessary
Do not include API keys, passwords, tokens, personal data, or other secrets in a report.
The project should:
- Store API keys and credentials in environment variables.
- Never commit
.envfiles containing real secrets. - Keep
.env.examplelimited to variable names and safe placeholders. - Validate user-controlled input on the server.
- Treat AI output as untrusted data.
- Validate structured AI responses before using them.
- Enforce round expiration on the server where applicable.
- Prevent duplicate/replay submissions.
- Apply appropriate rate limiting to public endpoints.
- Avoid exposing internal stack traces or secrets to users.
- Log diagnostics without logging credentials or sensitive data.
- Keep dependencies reasonably up to date.
- Run security and failure tests before deployment.
User-provided text may be sent to an AI provider. AI-generated content must not be treated as trusted input.
The application should:
- validate AI responses
- handle malformed or empty responses
- handle provider timeouts and rate limits
- protect system instructions and internal configuration
- constrain prompt-injection attempts where appropriate
- keep API credentials on the server
- avoid storing unnecessary user content
Only test the application and services you are authorized to test.
Resilience and audit features are intended for controlled testing of this application's own failure-handling behavior.