Skip to content

Security: AloneMath/S-Assistant-Box

Security

SECURITY.md

Security Policy

Scope

S Assistant Box is a research prototype. It may load local model checkpoints, curriculum files, SQLite memory databases, and event logs. Treat all imported content as untrusted input.

Reporting a vulnerability

Please do not publish credentials, private data, or an exploitable proof of concept in a public issue. If GitHub private vulnerability reporting is enabled, use that channel. Otherwise, open a minimal issue without secrets and request a private contact channel.

Before opening a pull request

  • Never commit API keys, access tokens, passwords, or private URLs.
  • Never commit model checkpoints, optimizer states, downloaded datasets, or local box_runs/ output.
  • Use synthetic examples when demonstrating memory, curriculum, or reasoning.
  • Review generated diffs and GitHub's secret-scanning alerts before publishing.

Safe operation

Run the Box with least-privilege filesystem access. Keep network retrieval and external tools disabled unless their sources and outputs are explicitly logged and reviewed.

There aren't any published security advisories