Skip to content

Security: tendaigomo/NerfWatch

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

Do not open public issues for security vulnerabilities.

Please report security issues through GitHub Security Advisories. This ensures the report is private and allows coordinated disclosure.

You should receive an acknowledgment within 72 hours. We will work with you to understand the issue, confirm it, and coordinate a fix before public disclosure.

Scope

The following are in scope for security reports:

  • NerfWatch CLI tool -- vulnerabilities in the Go codebase, command handling, or data processing
  • Configuration file handling -- issues with how NerfWatch reads, writes, or protects nerfwatch.yaml and probes.yaml
  • SQLite database security -- unauthorized access, injection, or data leakage from the local metrics database
  • Docker sandbox execution -- container escape, privilege escalation, or insecure defaults in code probe sandboxing

Out of Scope

The following are not in scope:

  • Provider API security -- vulnerabilities in Anthropic, OpenAI, Google, or xAI APIs themselves (report those to the respective providers)
  • Model behavior -- unexpected model outputs, hallucinations, or reasoning failures (these are what NerfWatch monitors, not security issues in NerfWatch itself)
  • Social engineering of project maintainers

Security Design

NerfWatch handles sensitive data (API keys) and follows these practices:

  • API keys are encrypted at rest in the credstore at ~/.nerfwatch/credentials.enc (AES-256-GCM with an Argon2id-derived key, OWASP offline-attack parameters). The YAML configuration file (nerfwatch.yaml) holds only opaque api_key_ref: pointers - never plaintext keys. Both the credstore and nerfwatch.yaml are written with mode 0600. Environment variable overrides (NERFWATCH_*_API_KEY) let users keep keys out of the filesystem entirely. NerfWatch does not transmit API keys anywhere other than to the configured provider APIs. See docs/auth.md for the credential lifecycle.
  • The SQLite database stores derived metrics and raw probe artifacts, including rendered prompts, model response text, and thinking / chain-of-thought text. The database file is created with mode 0600 (owner-only).
  • Alert content contains only derived metrics (scores, control chart values, trend indicators). Raw model reasoning text is never included in alerts or notifications.
  • Code probes execute inside Docker containers with restricted capabilities. The sandbox configuration is defined in sandbox/.

Supported Versions

Security fixes are applied to the latest release only. We recommend always running the most recent version of NerfWatch.

There aren't any published security advisories