fable-agent/SECURITY.md

1.1 KiB

Security

Prompt and repo safety

fable-agent may read untrusted markdown, tickets, repos, and model output. Treat all of it as data, not instructions.

  • Do not paste, vendor, replay, or execute leaked proprietary system prompts.
  • Do not use permission-bypass flags.
  • Send model prompts through stdin or structured APIs, not shell-interpolated command strings.
  • Keep secrets in environment variables; never hardcode fallback API keys or local key paths.
  • Run code-changing agents in scoped workspaces/worktrees when possible.
  • Keep docs and CLI parity green with npm run -s docs:check before publishing.

Defensive Fable-style profile

Allowed: multi-model fan-out plus judge synthesis, citations for factual/current claims, refusal/reformulation for harmful requests, bounded loops with validation evidence.

Not allowed: leaked prompt reproduction, prompt-extraction recipes, jailbreak/sandbox-bypass instructions, autonomous execution without permission boundaries.

Reporting

Open an issue with reproduction steps, affected version/commit, and impact. Do not include live secrets or proprietary prompt text.