HuggingClaw / SECURITY.md
somratpro's picture
Upload 12 files
d41fe21 verified

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT open a public issue
  2. Email the maintainer or open a private security advisory on GitHub
  3. Include steps to reproduce if possible

We'll respond within 48 hours and work on a fix.

Security Best Practices

When deploying HuggingClaw:

  • Set your Space to Private β€” prevents unauthorized access to your gateway
  • Use a strong GATEWAY_TOKEN β€” generate with openssl rand -hex 32
  • Keep your HF token scoped β€” use fine-grained tokens with minimum permissions
  • Don't commit .env files β€” the .gitignore already excludes them
  • Use TELEGRAM_USER_ID β€” restricts bot access to your account only
  • Review logs regularly β€” check for unauthorized access attempts

Supported Versions

Version Supported
1.0.x βœ