Skip to content

Security: tradecatlabs/human_infra

Security

SECURITY.md

Security Policy

This repository is primarily documentation and lightweight public-data tooling, but it still contains safety-sensitive material.

Scope

Security and safety reports are relevant when they involve:

  • scripts that mishandle network input, files, paths, or generated data;
  • data provenance mistakes that could mislead health or safety interpretation;
  • documentation that enables unsafe medical, neural, memory, or human experimentation behavior;
  • privacy leaks, credentials, private notes, or unintended personal data;
  • instructions that could be used for coercive monitoring or manipulation.

Out of Scope

  • General disagreement with a domain model or theory.
  • Requests for medical advice.
  • Requests for invasive neural, memory editing, or human experimentation steps.

Reporting

Do not publish sensitive exploit details, private data, or unsafe procedural steps in a public issue.

If this repository is made public, add a private security contact here. Until then, report directly to the repository owner.

Handling Rules

  • Preserve evidence.
  • Minimize exposure.
  • Remove secrets or private data immediately after confirming scope.
  • Document the root cause and prevention rule in the appropriate docs/ or domains/*/AGENTS.md file when it has long-term value.

There aren't any published security advisories