mirror of
https://github.com/HKUDS/OpenSpace.git
synced 2026-09-24 00:55:36 +00:00
Changes: - Disable telemetry by default (opt-in instead of opt-out) - Strip user query text and LLM response text from telemetry events - Remove server_identifiers and tools_available_names from telemetry - Default search_scope to 'local' (no auto-import of unverified cloud skills) - Default auto_import to False in search_skills - Scope OpenClaw credential reading to openspace env block only - Enable sandbox by default in security config - Add SECURITY.md with guidance for users See PR description for full security audit findings.
25 lines
1.5 KiB
Markdown
25 lines
1.5 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting Vulnerabilities
|
|
|
|
If you discover a security vulnerability, please report it responsibly by opening a private security advisory on this repository. Do **not** open a public issue.
|
|
|
|
## Security Considerations for Users
|
|
|
|
OpenSpace is a powerful agent framework that can execute shell commands, run arbitrary code, and connect to external services. Users should be aware of the following:
|
|
|
|
### Telemetry
|
|
|
|
Telemetry is **disabled by default** as of this PR. If you opt in by setting `MCP_USE_ANONYMIZED_TELEMETRY=true`, be aware that execution metadata (model names, tool usage counts, timing) is sent to PostHog and Scarf. Query text and response text are **never** transmitted regardless of this setting.
|
|
|
|
### Cloud Skills
|
|
|
|
Cloud skill search and auto-import are **disabled by default** (`search_scope="local"`). If you enable cloud search (`search_scope="all"`), downloaded skills are not sandboxed or signature-verified. Only enable this in trusted environments.
|
|
|
|
### Host Config Auto-Detection
|
|
|
|
OpenSpace reads host agent configs (`~/.openclaw/openclaw.json`, `~/.nanobot/config.json`) to auto-detect LLM credentials. It only reads from the explicitly scoped `openspace` env blocks — not top-level or unrelated configuration sections.
|
|
|
|
### Shell Execution
|
|
|
|
The grounding engine can execute shell commands. The `config_security.json` defines blocked command lists, but this is a denylist approach. For production deployments, enable sandboxing (`sandbox_enabled: true`) and review the security policy configuration.
|