Skip to content

Latest commit

 

History

History
93 lines (66 loc) · 4.51 KB

File metadata and controls

93 lines (66 loc) · 4.51 KB

🔒 Security Policy — marko1olo/token-audit

Vulnerability Disclosure, Threat Modeling & Defensive Architecture
Maintained by the Жирняк & Адольф Петушков Engineering Syndicate
Project Scope: Token Audit LLM Token Cost Waterfall & BPE Tokenizer Visualizer


📑 Table of Contents

  1. 🛡️ Supported Versions & Patch Lifecycle
  2. 🎯 Domain Threat Model & Attack Surfaces
  3. 🚨 Vulnerability Reporting & Disclosure Protocol
  4. ⏱️ Response SLAs & Remediation Timelines
  5. 💎 Defensive Engineering Architecture
  6. 🔍 Dependency Auditing & Supply Chain Safety
  7. 👥 Syndicate Security Contacts

🛡️ 1. Supported Versions & Patch Lifecycle

We actively maintain and provide critical security updates for the following release lines of marko1olo/token-audit:

Branch / Release Supported Patch Cadence Notes
main (Head) ✅ Yes Immediate Hotfix Primary development target; fully patched.
Latest Tagged Release ✅ Yes Within 48 Hours Critical vulnerabilities backported.
Historical / Deprecated ❌ No None Please rebase or upgrade to current branch.

🎯 2. Domain Threat Model & Attack Surfaces

Security engineering in marko1olo/token-audit is guided by the following domain-specific threat vector analyses:

1. XSS via Prompt Rendering

  • Description: Malformed HTML/JS snippets inside analyzed prompt strings executing during token highlighting.
  • Impact Rating: HIGH / CRITICAL
  • Mitigation Strategy: Strict schema validation, boundary fuzz testing, and automated static security analysis.

2. Client Resource Exhaustion

  • Description: Multi-megabyte inputs locking the main UI thread during synchronous BPE regex splitting.
  • Impact Rating: HIGH / CRITICAL
  • Mitigation Strategy: Strict schema validation, boundary fuzz testing, and automated static security analysis.

3. Supply Chain Poisoning

  • Description: Malicious updates to third-party tokenizer vocabulary packages.
  • Impact Rating: HIGH / CRITICAL
  • Mitigation Strategy: Strict schema validation, boundary fuzz testing, and automated static security analysis.

🚨 3. Vulnerability Reporting & Disclosure Protocol

If you discover a security flaw or exploit vector in marko1olo/token-audit, do NOT post it publicly in open issues or discussions.

3.1 Submission Workflow

  1. Navigate to the Security tab on GitHub -> Advisories -> Report a vulnerability.
  2. Alternatively, open a cryptographically signed advisory to the syndicate maintainers.
  3. Provide the following details:
    • Subsystem and affected source files / line numbers.
    • Step-by-step minimal reproduction script or payload.
    • Assessment of potential exploit impact (memory corruption, data exfiltration, DoS).

⏱️ 4. Response SLAs & Remediation Timelines

  • Initial Triage & Acknowledgment: Within 24–48 hours.
  • Vulnerability Verification & Reproducer: Within 3 business days.
  • Remediation Patch Development: Within 7 business days.
  • Public Coordinated Disclosure: Published simultaneously with the verified patch release.

💎 5. Defensive Engineering Architecture

All code running in this repository must adhere to defensive coding invariants:

  • Memory Bounds Checking: All slice offsets, vector indices, and WebAssembly linear memory allocations are strictly bounded.
  • Input Sanitization: External network payloads, uploaded files, and deserialized states must be validated before ingestion.
  • Cryptographic Rigor: Sensitive tokens, cryptographic keys, and hashes must use standard constant-time comparison algorithms to eliminate timing side-channels.

🔍 6. Dependency Auditing & Supply Chain Safety

  1. Automated daily vulnerability scans on all dependencies via npm audit / cargo audit / pip-audit.
  2. All lockfiles are committed and pinned to immutable cryptographic hashes.
  3. Third-party vendor updates require manual review of code diffs to prevent supply chain poisoning.

👥 7. Syndicate Security Contacts

Developed, audited, and maintained under the security direction of Жирняк & Адольф Петушков.