|
Download docs/SECURITY.md from devildasdf/NEXORA: direct link, hf CLI and curl.
- Browser
- Download file 3.16 kB
-
https://huggingface.co/devildasdf/NEXORA/resolve/main/docs/SECURITY.md
- Command line
-
hf download hf://devildasdf/NEXORA/docs/SECURITY.md
-
curl -L -o SECURITY.md https://huggingface.co/devildasdf/NEXORA/resolve/main/docs/SECURITY.md
3.16 kB
| # Authority and privacy boundaries | |
| NEXORA is a local research runtime, not a hardened sandbox or certified security product. | |
| * Model messages recommend actions; Executor applies schema, permissions, relative paths, configured command names and limits. | |
| * READ permits bounded text inspection and listing. WRITE uses atomic replacement and requires an observed hash for existing files. EXECUTE is separately enabled and host execution defaults off. | |
| * Path resolution rejects traversal, resolved symlinks outside root, Windows drive/ADS syntax and named private/control directories. There are TOCTOU and platform reparse-point limitations; do not share writable roots with adversarial processes. | |
| * A Python, shell, compiler or test executable can run repository code with the host user's authority. Command allowlisting and environment trimming are not an OS sandbox. Network denial is not implemented for host children. | |
| * Subprocess timeouts attempt tree termination; detached descendants can outlive containment assumptions. Use cgroups/namespaces or an isolated VM/service for untrusted work. Durable exactly-once external action semantics are not implemented. | |
| * Tool outputs are labeled untrusted data. This instruction alone is not an injection-resistance guarantee. Permission checks still apply even if the model follows injected text. | |
| * Verifiers must be owner selected and independent of writable model outputs. Do not let the model change tests/reward code or choose its success oracle. Truncated output cannot establish full observed state. | |
| * Default audit logs store IDs, timing/status and hashes, not arguments or content. The optional agent result trace includes tool output and must be treated as potentially private. | |
| * Memory is plaintext local SQLite. Storage encryption, multi-user ACLs and backup key management are deployment responsibilities. Delete/correct/expire operations are implemented; copied backups require their own retention policy. | |
| * Remote inference requires explicit opt-in and can send prompts/retrieved content to the chosen endpoint. Redirects and environment proxies are disabled in the HTTP client. Do not use cleartext HTTP across an untrusted network. | |
| * Local server requires a token, accepts loopback connections, rejects browser-origin POSTs, and serializes generation. It is not an internet-facing production HTTP server and is not protected against every local denial-of-service attack. | |
| * Data/failure secret-pattern handling is incomplete by design. License allowlists cannot establish rights to arbitrary content merely labeled with a permitted license. | |
| * Model files use safetensors for inference. Optimizer checkpoints are project-produced PyTorch state loaded with `weights_only=True`; checksum integrity does not prove an untrusted publisher is safe. | |
| Before production: external execution isolation, adversarial injection suite, immutable hidden tests, scoped short-lived credentials, network egress controls, OS-specific filesystem tests, durable action reconciliation, resource quotas, server hardening and incident recovery drills are required. No such production certification is claimed in this release. | |