Do not open public issues for security vulnerabilities.
Please report security issues through GitHub Security Advisories. This ensures the report is private and allows coordinated disclosure.
You should receive an acknowledgment within 72 hours. We will work with you to understand the issue, confirm it, and coordinate a fix before public disclosure.
The following are in scope for security reports:
- NerfWatch CLI tool -- vulnerabilities in the Go codebase, command handling, or data processing
- Configuration file handling -- issues with how NerfWatch reads, writes, or protects
nerfwatch.yamlandprobes.yaml - SQLite database security -- unauthorized access, injection, or data leakage from the local metrics database
- Docker sandbox execution -- container escape, privilege escalation, or insecure defaults in code probe sandboxing
The following are not in scope:
- Provider API security -- vulnerabilities in Anthropic, OpenAI, Google, or xAI APIs themselves (report those to the respective providers)
- Model behavior -- unexpected model outputs, hallucinations, or reasoning failures (these are what NerfWatch monitors, not security issues in NerfWatch itself)
- Social engineering of project maintainers
NerfWatch handles sensitive data (API keys) and follows these practices:
- API keys are encrypted at rest in the credstore at
~/.nerfwatch/credentials.enc(AES-256-GCM with an Argon2id-derived key, OWASP offline-attack parameters). The YAML configuration file (nerfwatch.yaml) holds only opaqueapi_key_ref:pointers - never plaintext keys. Both the credstore andnerfwatch.yamlare written with mode0600. Environment variable overrides (NERFWATCH_*_API_KEY) let users keep keys out of the filesystem entirely. NerfWatch does not transmit API keys anywhere other than to the configured provider APIs. See docs/auth.md for the credential lifecycle. - The SQLite database stores derived metrics and raw probe
artifacts, including rendered prompts, model response text, and
thinking / chain-of-thought text. The database file is created with
mode
0600(owner-only). - Alert content contains only derived metrics (scores, control chart values, trend indicators). Raw model reasoning text is never included in alerts or notifications.
- Code probes execute inside Docker containers with restricted capabilities. The sandbox configuration is defined in
sandbox/.
Security fixes are applied to the latest release only. We recommend always running the most recent version of NerfWatch.