Spaces:
Paused
Paused
Security
HuggingMes runs a full agent gateway with tool access. Treat the Space and its secrets like a server.
Required Hardening
- Set
GATEWAY_TOKEN;/v1/*routes requireAuthorization: Bearer <GATEWAY_TOKEN>. - Set
TELEGRAM_ALLOWED_USERSto numeric Telegram user IDs. - Keep your HF Dataset backup private.
- Do not enable
SYNC_INCLUDE_ENV=trueunless you intentionally want/opt/data/.envbacked up.
Reporting
Open a private issue or contact the maintainer directly with reproduction steps and affected configuration.