The per-repo gate flagged four ERRORs and two WARNs. Fixed, in the order the work actually gets done in: MISSING - `## Honest limitations` -> `## Known limitations`, `## Out-of-scope (documented boundary)` -> `## Non-goals`. Both sections existed under names no reader or agent scans for; the contract wants predictable top-level headings. Pointers followed: the in-README anchor, SECURITY.md's out-of-scope preamble, CONTRIBUTING.md's scope section, and the consumer-facing docs/ADOPTION-BRIEF.md. Historical records (CHANGELOG, docs/PLAN.md, docs/OKF-INGESTION-BRIEF.md) keep the name they were written with. WEAKENING - README now opens with one line identical to the forge description, above the badges. That is the only place a machine can check description == README. - Forge description shortened 207 -> 178 codepoints (bound 180), and the same string written to pyproject's `description` so the fourth copy cannot drift. The tests badge is dropped, not updated. `tests-699_passing` as a static image is a claim dressed as evidence: there is no CI runner on this forge, so nothing verifies it. Replaced with the honest substitute in Install — the single command that runs the suite from a clean clone, stated together with the fact that nothing runs it automatically. Two WARNs deliberately left standing: - H1 `# llm-ingestion-guard` != repo name. The register itself records llm-ingestion-guard as "a package, not a repo"; the H1 names what you pip install. Renaming the repo is the operator's call, not this commit's. - The `Status` badge trips the same claim-badge regex, but `alpha` asserts maturity, not a run — the same reason version/license/platform are exempt. Measured false positive in the gate's classifier, reported upstream.
2.5 KiB
Security policy
llm-ingestion-guard is a defensive library for LLM ingestion pipelines. Its own
security posture matters: a flaw here can silently admit a poisoned artifact into a
downstream corpus. Reports are welcome.
Supported versions
The project is pre-1.0 (0.2.x, alpha). Only the latest published version receives
fixes; there are no back-ported security branches yet. Pin a version and watch the
CHANGELOG.md ### Security entries.
Reporting a vulnerability
Do not open a public issue for a vulnerability. Public disclosure before a fix gives an attacker a window against every downstream consumer.
Instead, report it privately to the maintainer via the canonical repository on Forgejo:
- Repository:
git.fromaitochitta.com/open/llm-ingestion-pipeline-security - Contact the maintainer directly through that Forgejo instance (private message /
maintainer contact) and mark the subject
SECURITY.
Please include:
- affected version / commit,
- a minimal reproduction (input → observed disposition/finding vs. expected),
- the impact you see (e.g. a poisoned artifact that disposes
WARNinstead ofFAIL_SECURE).
Obfuscate any real payloads the same way the test corpus does — build attack strings
from chr(0x…) fragments so the report itself does not ship a live carrier.
What counts as a vulnerability
In scope (a real finding):
- a bypass of a stated control — e.g. an invisible carrier that reaches the
persist gate without failing secure, a credential that egresses without a
decoded:egress:*/egress:*label, aguard()path that fails open; - a
prepare_input/screen_outputcode path that raises instead of failing closed; - a ReDoS or unbounded-resource input against the scanner.
Out of scope (documented boundaries — see the Known limitations section of
README.md, not vulnerabilities):
- semantic / factual poisoning invisible to lexicon + entropy;
- a HIGH finding in trusted prose disposing to
WARN(§4.7 trust-scaling); - hex-wrapped (non-base64) secret egress;
- multimodal / binary-layer carriers (OCR, font stego, VBA/macros, encrypted files);
- the multilingual homoglyph-mix false positive.
If you are unsure whether something is in scope, report it privately anyway.
Disclosure
This is a small project without a formal embargo SLA. The maintainer will
acknowledge a report, agree a fix + disclosure timeline with the reporter, and
credit the reporter in the CHANGELOG.md ### Security entry unless they prefer to
remain anonymous.