Skip to content

Security: gabazureus/jev-ragcheck

Security

SECURITY.md

Security Policy

Supported versions

Only the latest release receives fixes while the project is in alpha (0.x).

Reporting a vulnerability

Please do not open a public issue. E-mail gabriel.br@gmail.com with a description, a reproduction and the impact you expect. You will get an acknowledgement within 5 working days.

Threat model in brief

  • API keys are read from the environment (TYPESAFE_API_KEY, OPENROUTER_API_KEY) and are never logged or written to results. The optional decision cache stores questions and answers, not keys.
  • Your data leaves your machine. The question, the retrieved passages and the answer are sent to the configured Jev provider. Do not evaluate data you are not allowed to share with it.
  • Untrusted content. Retrieved passages and answers are treated as data inside typed questions; jev-ragcheck never executes them and never follows instructions inside them. A passage that tries to manipulate the judgement can still influence a model's decision, so do not use a single evaluator score as the only gate for high-stakes actions.
  • HTML reports escape all text and embed data as JSON with </ escaped.

There aren't any published security advisories