Sandboxed Lua
Environment access is denied unless the operator allowlists each name.
Inspect the control01 / SECURITY POSTURE
The project takes the same stance as the runtime: denied by default, bounded where enabled, and inspectable after execution.
02 / RUNTIME SECURITY
Controls are applied at the runtime boundary instead of delegated to prompt wording.
Environment access is denied unless the operator allowlists each name.
Inspect the controlShell is opt-in. Approval gates redact arguments and fail closed on timeout.
Inspect the controlSSRF controls, CORS, rate limits, and request and response size limits protect serve mode.
Inspect the controlCross-replica human answers use an encrypted PostgreSQL mailbox and stay attributed.
Inspect the control03 / SUPPLY CHAIN
The release is a chain of source, artifacts, identities, and checks—not a binary attached to a tag.
Release archives are bound to published SHA-256 checksums.
Release assets carry identity-bound signing evidence.
Each release exposes the dependency inventory used for review.
Container promotion is tied to a signed release receipt and immutable source inputs.
04 / DEPLOYMENT GUIDANCE
Run as a non-root user, set resource limits, preserve graceful shutdown, and size storage and routing around the chosen persistence mode.
05 / RESPONSIBLE DISCLOSURE
Use GitHub private vulnerability reporting. Do not put an undisclosed vulnerability in a public issue.
A maintainer will acknowledge a valid private report, preserve a direct technical channel, and coordinate disclosure around a verified fix. Response timing is best effort unless a support contract defines an SLA.
Open private reportingLICENSE + PROVENANCE
BRING THE REVIEW QUESTIONS