S Assistant Box is a research prototype. It may load local model checkpoints, curriculum files, SQLite memory databases, and event logs. Treat all imported content as untrusted input.
Please do not publish credentials, private data, or an exploitable proof of concept in a public issue. If GitHub private vulnerability reporting is enabled, use that channel. Otherwise, open a minimal issue without secrets and request a private contact channel.
- Never commit API keys, access tokens, passwords, or private URLs.
- Never commit model checkpoints, optimizer states, downloaded datasets, or
local
box_runs/output. - Use synthetic examples when demonstrating memory, curriculum, or reasoning.
- Review generated diffs and GitHub's secret-scanning alerts before publishing.
Run the Box with least-privilege filesystem access. Keep network retrieval and external tools disabled unless their sources and outputs are explicitly logged and reviewed.