Skip to content

Security: CinvanaAI/builder-prototypes

Security

SECURITY.md

Security

This library is an orchestration core, not a sandbox.

  • Registered step functions are trusted Python and have the host process's authority.
  • Prompt text and returned payload values may contain private data; compact evidence intentionally omits them, but callers still own payload storage.
  • The intake writer validates filename components, bounds writes to the resolved queue directory, refuses overwrite, and uses atomic replacement.
  • There is no network or provider adapter in the public package.
  • There is no code installer or subprocess runner in the public package.

Do not add dynamic imports, arbitrary file paths, generated-code execution, or a live provider without a separate threat model and tests.

There aren't any published security advisories