Skip to content

Security: Keitark/chatpcba

Security

SECURITY.md

Security policy

Reporting

Please report vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue containing credentials, private design data, supplier-account information, or an exploitable registry detail.

Secrets

CHATPCBA_REGISTRY_TOKEN is an operator secret. It must remain outside the plugin package, Git history, PCBA evidence receipts, and screenshots.

Data boundary

The Evolution Registry adapter derives a one-way workspace fingerprint locally and sends evidence basenames only. It must not send native design sources, absolute paths, replay commands, or account/order data.

Engineering skills can inspect user-provided project files. Users remain responsible for deciding which proprietary designs may be processed or shared.

There aren't any published security advisories