Skip to content

Security: morriss-group/vapi-voice-tuneup

Security

SECURITY.md

Security

  • Reporting: if you find a secret, a customer's data, or a way to make the tools server do something it should not, open an issue at github.com/morriss-group/vapi-voice-tuneup/issues with the file and line and no values. Same-day reply.
  • What the tools server protects: every request to /vapi must carry the shared secret; a deploy with no secret configured refuses everything rather than letting everything through (tools-server/server.js, requireSecret). GET /status reports whether the secret is configured and never its value.
  • History note (September 3, 2026): commit 0658ed8 removed latency/ because it named the shop and held two weeks of its call statistics (counts, gaps, tool timings), which the author judged were the business's own numbers to publish or not. The measuring script's own header says no caller is identified in its output; no customer data and no credentials were in either file. A sanitized version of the results came back later as latency/RESULTS.md. The pre-sanitized copy (commit 3d1e43c, still in history) also carried the working-folder names of two of the shop's private repositories and the first characters of the assistant's id: identifiers, not credentials. The owner chose on September 14, 2026 not to rewrite that history, because doing so would move the 2026-09-22-v4b release and break every existing copy; that decision stands and is recorded here instead. The file stays in git history on purpose; rewriting history would break the release tags builders watch.
  • What is never in this repository: live credentials, the shop's system prompt, customer names or numbers. The tuning logs replace real surnames with placeholders.
  • History note (September 23, 2026): two test fixtures added at 6:05 AM CT did not meet this file's own rule. The tip was corrected at 7:22 AM and the four commits from that morning were rewritten at 7:28 AM by the owner; the tag 2026-09-23-review-round-one moved with them. If you cloned or pulled between 6:05 and 7:30 AM CT on September 23, 2026, delete that copy and clone again. An outside reader caught it within the hour; that is what the reporting line above is for. GitHub Support purged the four unreachable commits on September 24, 2026 (ticket 4786097); each old commit URL, raw-file URL, and API lookup was checked at 7:14 AM CT and returns not-found. Nothing in those commits was a credential, so nothing had to be rotated.

There aren't any published security advisories