Skip to content

Security: drjoykarmakar/BioAgent-X

Security

SECURITY.md

Security and responsible use

Scope and support

BioAgent-X 0.1.x is an experimental research preview. Security fixes are intended for the current development branch; no response-time or long-term-support commitment is implied.

Reporting

Do not include API tokens, confidential molecules, patient data, unpublished training data, or working exploit payloads in public issues. Use GitHub's private vulnerability reporting UI when it has been enabled for this repository. If that option is unavailable, open a public issue asking for a private contact channel without disclosing the vulnerability or sensitive material. The maintainer must review and enable private reporting in repository settings; it is not activated by this file.

Operational controls

  • Keep .env files and API credentials outside Git. Rotate exposed keys.
  • Treat checkpoints, dependencies and LLM endpoints as trusted inputs requiring review. Hash checking detects changes but does not establish trust in an attacker-controlled manifest.
  • Do not provide untrusted pull requests with production secrets. Test and build workflows use read-only repository permissions. Only the gated release job receives contents: write and uses the built-in GitHub token.
  • Validate assay context, data licensing and downstream research suitability. This software is not a medical device, treatment recommendation, or substitute for experimental, toxicological and clinical evaluation.

No confidential external data or pretrained weights are included in this source release. Baseline secret-pattern tests are not a comprehensive security audit.

There aren't any published security advisories