Skip to content

Security: Regulus-24/SceneGuard

Security

SECURITY.md

Security and deployment scope

SceneGuard is a local research/demo prototype. Bind the workbench to 127.0.0.1; it is not a hardened multi-user internet service. Human approval UI identity is a local demo identity, not enterprise authentication.

Local runtime bootstrap creates passwords and tokens on the receiving device. .local-runtime/, .semifinal-demo-jobs/, .runtime-test/ and other generated runtime directories must remain private. Never attach their contents to public issues.

Agents have role- and job-bound tool grants. Approval and publish boundaries must not be bypassed. Missing required checks, stale evidence, changed candidate hashes and uncertain executor outcomes must block acceptance or trigger review.

For a suspected vulnerability, avoid publishing exploit details or secrets in a public issue. Contact the repository owner through an appropriate private channel. This repository does not provide a production security guarantee.

There aren't any published security advisories