If you discover a security issue in Horosa Skill, please avoid opening a public issue with sensitive exploit details.
Instead, report:
- the affected area
- impact
- reproduction details
- any suggested mitigation
through a private channel controlled by the maintainer.
Security-sensitive areas in this repository include:
- runtime archive installation
- manifest-driven asset download
- local process startup and shutdown
- local storage of structured run artifacts
- MCP exposure on local interfaces
- Report output paths are untrusted input. MCP callers are language models, so
output_pathmay come from prompt injection. Report tools only write under the configured output directory or the roots listed inHOROSA_REPORT_OUTPUT_ROOTS; anything else fails withreport.output_path_not_allowedand writes nothing. The three report tools are annotateddestructiveHint=true. - HTTP transport is opt-in and token-gated.
serve --transport streamable-httprequires a bearer token (--token/HOROSA_MCP_TOKEN; 401 without it) and validatesHostagainstHOROSA_ALLOWED_HOSTS(421 otherwise). Exposing it on a public interface without an authenticating gateway makes your local memory store readable by anyone — seehorosa-skill/examples/clients/remote-connectors-oauth-gateway.md. - Process control never targets processes we did not start. Stop / restart require strong ownership evidence
(
runtime/identity.py); the stop script scopes kills by runtime root; Windows liveness probes useOpenProcess, neveros.kill. - The optional cloud decision layer (TypeSafe Jev) is off by default. When enabled,
HOROSA_JEV_SCOPE=metasends only redacted question metadata;snapshot(needed by the faithfulness / hecan surfaces) additionally sends export-snapshot text.HOROSA_JEV_API_KEYis never logged, never printed bydoctor, and never written into client configs or reports. - Client-config writes are minimal and reversible.
setup --writeonly upserts its own server entry, keeps a.horosa-bak, replaces atomically, and refuses shapes it cannot parse.
- do not weaken checksum validation paths
- do not add hidden external network dependencies to offline flows
- keep local runtime execution explicit and inspectable
- prefer least-surprise defaults for ports, paths, and file writes