Atraium can interact with model providers, files, processes, local applications, plugins, MCP servers, and computer-use workflows. Security reports are taken seriously.
Only the latest published Atraium preview is considered for security fixes during the preview period.
| Version | Security consideration |
|---|---|
| Latest preview | Best-effort review and fixes |
| Older previews | Upgrade before reporting unless the issue prevents upgrade |
Do not disclose a suspected vulnerability in a public issue or discussion.
Use GitHub's private vulnerability reporting feature for this repository once it is enabled. Include:
- affected preview version;
- affected platform;
- concise impact description;
- reproducible steps;
- whether credentials, files, processes, or remote services are exposed;
- suggested mitigation, if known.
If private vulnerability reporting is temporarily unavailable, open a public issue containing only a request for a private contact channel. Do not include exploit details or sensitive evidence.
Atraium is a powerful local tool, not a sandbox. Depending on enabled capabilities, it may be able to:
- read or modify files;
- start or stop processes;
- interact with local applications;
- send content to configured providers;
- call external HTTP services;
- load plugins or MCP tools;
- hand work to computer-use flows.
Use a dedicated test workspace while learning the preview. Keep backups and review consequential operations.
Never place provider credentials in:
- GitHub issues;
- screenshots;
- shared logs;
- room prompts;
- source-controlled settings files;
- portable backup files.
Revoke a credential immediately if you believe it has been exposed.
Download preview binaries only from the official GitHub Releases page. Verify published SHA-256 checksums before running a release.