Security fixes are applied to the latest release on the default branch.
Do not open a public issue containing credentials, prompts, private API responses, or exploit details. After this repository is published on GitHub, use its private Security → Report a vulnerability form. Until then, report privately to the project owner who supplied this copy.
Include the affected version, reproduction steps using fake credentials, impact, and any proposed mitigation. Remove prompts, tool arguments, cookies, API keys, account identifiers, and raw provider responses.
- This proxy protects a locally configured upstream credential; it is not designed for direct internet exposure.
- Loopback binding and local bearer authentication are the supported deployment model.
- The proxy does not inspect or scrub prompt payloads. Anything a user intentionally sends may reach the configured provider.
- Cache status is
unknownunless an operator configures evidence documented by their provider. - The per-minute limiter is process-local. The UTC-day limiter persists in a local SQLite file and survives normal restarts; deleting or making that file unavailable changes the protection boundary.
- Rate and daily limits reduce accidental spend but cannot reverse already billed requests or guarantee a maximum currency amount.