47327d90d8
Bind commit/push/PR safety, gitea_vps-only remote ops, and secret scans in AGENTS.md, with CLAUDE.md and Grok rules so every harness loads them.
23 lines
938 B
Markdown
23 lines
938 B
Markdown
# Security Policy
|
|
|
|
## Product invariants
|
|
|
|
- Agent never executes payments, refunds, or bill-pay.
|
|
- Client outbound messages and social posts are draft-only unless a future gated send is explicitly designed.
|
|
- Secrets never commit to git (use OpenShell providers / host env).
|
|
- Agents: follow **Git hygiene** in [AGENTS.md](AGENTS.md) (secret scan before every commit; never put credentials in messages/PRs).
|
|
- Owner never receives host shell, Docker, or editor instructions from the assistant.
|
|
|
|
## Reporting
|
|
|
|
Report security issues privately to the repository maintainers (Ty_Tech org admins). Do not open public issues with secrets, tokens, or production PII.
|
|
|
|
## Dependencies
|
|
|
|
- Prefer pinned versions of NemoClaw, OpenShell, Hermes, and MCP packages.
|
|
- Automatic product updates are on by default; review release notes for major pins.
|
|
|
|
## Logging
|
|
|
|
Default log level is production (redacted). Do not enable trace in owner-facing demos.
|