Skip to content

Security: Amine-LG/jev-creature-forge

Security

SECURITY.md

Security policy

Jev Creature Forge is a localhost development application. The supported configuration binds to 127.0.0.1:8050; it is not a hardened public web service.

API keys

Use the in-app API settings dialog for an interactive session, or set TYPESAFE_API_KEY in the backend environment before startup. A key submitted through the dialog is retained only in process memory and forgotten when the server exits. The application must never write keys to repository files, browser storage, exports, receipts, logs, screenshots, or the budget ledger.

The UI and API never return a configured key. They expose only whether a key is configured and whether its source is session, environment, or none. Rotate any key that is accidentally committed, logged, shared, or pasted into an untrusted hosted instance.

Deployment boundary

Do not expose the included FastAPI/Uvicorn server directly to a public network. A hosted version would need independent user authentication, encrypted secret storage, CSRF and origin policy appropriate to its domain, rate limiting, HTTPS, operational monitoring, and a threat review. Those controls are intentionally outside this local studio.

Reporting

Report suspected vulnerabilities privately to the repository owner rather than opening a public issue containing secrets or exploit details. Include the affected revision and a minimal reproduction, but never include a live API key or private prompt receipts.

There aren't any published security advisories