8000 Security Overview · stl3/nobodywho · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Security: stl3/nobodywho

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability within NobodyWho, please follow these steps:

  1. DO NOT disclose the vulnerability publicly
  2. Send a direct message to the maintainers through:

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

We will acknowledge receipt of your report within 72 hours and will send you regular updates about our progress.

Security Considerations

NobodyWho runs LLMs locally on your machine. While this eliminates many traditional security concerns associated with cloud-based AI services, please be aware of:

  1. Model file integrity - Only download models from trusted sources
  2. Input validation - Be cautious with user input that gets passed to the LLM
  3. Output safety - LLM outputs should be treated as untrusted content

Responsible Disclosure

We kindly ask you to:

  • Give us reasonable time to fix the issue before disclosing it
  • Make a good faith effort to avoid privacy violations, data destruction, and service interruption
  • Not exploit the vulnerability beyond what is necessary to demonstrate the issue

There aren’t any published security advisories

0