Skip to content

Security: daemosofchaos/Atraium-Preview

Security

SECURITY.md

Security policy

Atraium can interact with model providers, files, processes, local applications, plugins, MCP servers, and computer-use workflows. Security reports are taken seriously.

Supported preview versions

Only the latest published Atraium preview is considered for security fixes during the preview period.

Version Security consideration
Latest preview Best-effort review and fixes
Older previews Upgrade before reporting unless the issue prevents upgrade

Reporting a vulnerability

Do not disclose a suspected vulnerability in a public issue or discussion.

Use GitHub's private vulnerability reporting feature for this repository once it is enabled. Include:

  • affected preview version;
  • affected platform;
  • concise impact description;
  • reproducible steps;
  • whether credentials, files, processes, or remote services are exposed;
  • suggested mitigation, if known.

If private vulnerability reporting is temporarily unavailable, open a public issue containing only a request for a private contact channel. Do not include exploit details or sensitive evidence.

Security boundaries

Atraium is a powerful local tool, not a sandbox. Depending on enabled capabilities, it may be able to:

  • read or modify files;
  • start or stop processes;
  • interact with local applications;
  • send content to configured providers;
  • call external HTTP services;
  • load plugins or MCP tools;
  • hand work to computer-use flows.

Use a dedicated test workspace while learning the preview. Keep backups and review consequential operations.

Provider credentials

Never place provider credentials in:

  • GitHub issues;
  • screenshots;
  • shared logs;
  • room prompts;
  • source-controlled settings files;
  • portable backup files.

Revoke a credential immediately if you believe it has been exposed.

Release verification

Download preview binaries only from the official GitHub Releases page. Verify published SHA-256 checksums before running a release.

There aren't any published security advisories