Skip to content

Security: idnwim/DemandScope-AI-v1.6.2

Security

SECURITY.md

Security Policy 安全说明

DemandScope AI is designed as a local-first Chromium extension plus a local Codex skill.

Data Boundaries

  • The Chrome and Edge extension packages do not request host_permissions.
  • The Chrome and Edge extension packages do not read cookies, passwords, browser history, private messages, or hidden page data.
  • The Chrome and Edge extension packages do not make external network requests.
  • Manual evidence is collected only from the currently active visible tab after the user clicks the extension.
  • Live AI search runs from the Codex skill, not from the extension, and requires the user's own EXA_API_KEY.

Secrets

Do not commit API keys, exported research packages containing private material, or downloaded evidence files with sensitive personal data.

Reporting Issues

For public GitHub use, open an issue with:

  • affected version,
  • browser and operating system,
  • reproduction steps,
  • screenshots or sanitized sample files when useful.

Do not paste private credentials, cookies, tokens, or personal data into issues.

There aren't any published security advisories