Claude Science Proxy (CSP) launches Claude Science in an isolated sandbox and routes model inference through a local, loopback-only proxy. Because it sits in the request path and handles third-party API keys, we take security reports seriously.
CSP follows a rolling release model. Only the latest release on the Releases page receives security fixes. Please upgrade before reporting.
| Version | Supported |
|---|---|
Latest release (main) |
✅ |
| Older releases | ❌ |
Do not open a public GitHub issue for security vulnerabilities.
Please use GitHub's private reporting channel:
- Go to the repository's Security tab → Report a vulnerability.
- Describe the issue, affected version, and reproduction steps.
- Do not include real API keys, tokens, or launch secrets — redact them.
If private advisories are unavailable to you, open a minimal public issue that says only "requesting a private security contact" (no details), and we will follow up.
- Acknowledgement as soon as the report is reviewed.
- A fix or mitigation plan for confirmed, in-scope issues, released in the next version.
- Credit in the release notes if you'd like it.
This is a small, community-maintained project — please allow reasonable time for a response before any public disclosure.
CSP's security model rests on a few invariants. Reports that show these being broken are especially valuable:
- Credential isolation — CSP must never read, copy, or leak real
~/.claude-scienceOAuth tokens or account state. The sandbox uses only a locally forged launch ticket, not an Anthropic credential. - Loopback-only proxy — the proxy binds to
127.0.0.1behind a per-session path secret and must not be reachable off-host. - Key handling — third-party API keys live in
~/.csp/CSP.json(mode0600), are passed to the proxy via environment variables, and are masked before reaching the frontend. Science's inboundAuthorization/x-api-keyheaders are stripped before your provider key is injected. - Sandbox/port isolation — sandboxed Science runs under an independent
HOME, port, and data directory; it must never collide with the real instance on port 8765.
- Vulnerabilities in Claude Science itself, or in third-party providers you route to (DeepSeek, GLM, Kimi, MiniMax, OpenRouter, etc.).
- Issues that require an already-compromised local machine or admin access.
- The app is not Apple-notarized yet; the first-launch Gatekeeper prompt is a known limitation, not a vulnerability.
CSP never transmits your keys anywhere except the provider endpoint you configure. If you believe a key was exposed (e.g. pasted into a log or issue), rotate it immediately at your provider.
CSP 处于推理请求路径上并管理第三方 API key,安全问题请认真对待。
- 仅支持最新版本,报告前请先升级到 最新 Release。
- 请勿公开提交安全漏洞。走仓库 Security → Report a vulnerability 私有上报;描述里不要包含真实 key/token/密钥。
- 重点范围:真实
~/.claude-science凭证隔离、代理仅监听127.0.0.1(带 path secret)、key 存于~/.csp/CSP.json(0600)且经环境变量传递并脱敏、沙箱使用独立HOME/端口(绝不占用真实端口 8765)。 - 不在范围:Claude Science 本身或第三方 provider 的漏洞、需要本机已被攻陷的问题、未公证导致的首次启动提示(已知限制,非漏洞)。
- 若怀疑 key 泄露(如粘进日志/issue),请立即到 provider 处轮换密钥。