Skip to content

Security: Robinson-AI-Lab/FridayOS1.0

Security

SECURITY.md

安全与隐私 · Security and Privacy

English

We pay attention to data leakage, unauthorized actions, prompt injection, and private information left in examples.

  • If a repository has enabled GitHub private vulnerability reporting, use its Security page.
  • Otherwise, open an Issue only to request a safe contact channel. Do not include exploit details, credentials, or personal data in public.
  • Where possible, provide affected versions, environment details, a minimal reproduction, and the expected impact, using fictional data.
  • Never upload credentials, private personnel records, internal files, or data you are not authorized to share.

Public source code does not determine where data goes during use. Review the actual models, plugins, services, and permissions in your setup.


简体中文

我们关注 AI 工具中的数据泄露、越权执行、提示注入以及示例材料中的隐私残留。

发现问题时

  • 如果仓库启用了 GitHub 私密漏洞报告,请通过 Security 页面使用该入口。
  • 如果没有可用的私密入口,可在 Issue 中仅请求维护者提供安全联系渠道;请勿附上漏洞利用细节、密钥或个人数据。
  • 报告中尽量提供受影响版本、环境、最小复现与影响说明,并使用虚构数据。

分享材料时

请勿上传凭据、真实人员资料、内部工作文件或未经授权的数据。示例优先使用虚构材料,实验记录应去除能够识别个人或组织的敏感信息。

公开仓库不代表使用过程中的数据会自动公开;请结合实际使用的模型、插件和服务检查数据流向与权限。

There aren't any published security advisories