← Files Empire LLM for CodexARCHIVED FILE
SECURITY.md
2.09 KB · Oct 2, 2026 · 00:29 UTC
# Security policy ## Supported version Security fixes currently target the latest `0.1.x` private-beta release. ## Report a vulnerability Do not open a public issue for credential exposure, path escape, secret leakage, provider spoofing, budget bypass, or unauthorized repository mutation. Email **team@empirellm.com** with a concise description and non-sensitive reproduction steps. Do not send API keys, keyring exports, real private source code, or raw provider responses. Revoke any credential that may have been exposed before reporting it. ## Credential handling - Enter provider credentials only through `$empire-settings` or the router's hidden setup prompt. - Never paste credentials into Codex chat, repository files, issues, pull requests, or logs. - Use provider-side spending limits and a dedicated key for Empire. - `doctor` reports presence and credential source only; it never prints values. - `logout` removes stored Empire credentials from the native system keyring. The project intentionally contains no production credentials. Offline tests use synthetic fixtures. ## Implemented safeguards - Outbound tasks, evidence, and media prompts are length-bounded and rejected when credential patterns or high-entropy secret material are detected. - Provider traffic is HTTPS-only, rejects embedded URL credentials and non-public targets, verifies TLS certificates, and refuses redirects so authorization headers cannot cross origins. - External-model output is treated as untrusted: only documented structured fields are retained, size and count limits are enforced, and secret-looking responses are rejected. - Provider output and handoff artifacts cannot write into the repository. Private state uses owner-only directories and atomic, mode-`0600` files. - Release ZIPs are built from an explicit allowlist with deterministic contents; private state, caches, key material, traversal paths, active SVG content, and dangerous Python execution constructs are checked before submission. See [SECURITY_TESTING.md](SECURITY_TESTING.md) for reproducible commands, results, benchmark mappings, and the limits of these tests.
SHA-256: 8985b15863682262c16ba8ee3e9c0b4e08c3d39196cc83f0be98bca5b78da289