The SDK provides explicit validation, identity and network boundaries. Your application remains responsible for permissions, source rights, secret handling and how agents use fetched content.
Trust boundaries
| Boundary | Current protection | Limit |
|---|---|---|
| JSON input | Strict parsing; schema and semantic validation; named refusals | A valid record can still contain a false claim |
| Content identity | Canonical record digests and exact-byte source digests | A digest alone does not establish author, truth or publication time |
| Local storage | Append-only records, revision references and single-writer lock | No independent checkpoint; whole-store replacement or complete index-tail removal may go undetected |
| Provider network reads | HTTPS allowlist, bounded redirects/retries, size and time limits | The remote provider's text remains untrusted |
| Evaluation | Pinned inputs/rule and separate reproduction | Only the implemented binary rule and supported eligibility contract |
| Source selectors | Check selectors against supplied content | The core never fetches missing source bytes |
Protect agent integrations
Treat source text, article excerpts, provider descriptions and dataset metadata as data. An instruction inside an article is not permission to run a command, change a tool policy or disclose an environment variable.
The library is not a general prompt-injection filter. Applications should separate trusted instructions from retrieved evidence, constrain agent tool permissions and require their own authorization for side effects. Do not describe schema validation as complete protection against prompt injection.
Keep private information out of shared records
- Include only source material you are allowed to retain or redistribute.
- Do not put API keys, portfolio positions, personal data or internal prompts into examples or shared records.
- Avoid signed URLs or query-string tokens. User-info credentials in locators are refused, but not every query-string secret can be detected automatically.
- Use explicit withheld markers only where the schema permits them. A marker records a disclosure limitation; it is not encryption.
- Share selected exported records and permitted source bytes. A raw store's
writer.lockmay contain local host, process and time metadata.
The SDK provides no encryption service, remote key management or automatic anonymization. Those require an application design and separate controls.
Offline and network behavior
comuvia has no runtime dependencies and performs no network fetch. foreglass makes requests only through explicit client fetch methods. Its replay path stays offline and marks replayed input synthetic. Neither package adds a telemetry service.
These documentation pages add no automatic provider requests, telemetry or feedback submission. Downloaded examples run under your control. The surrounding website has its own privacy policy.
Report a vulnerability
Report privately through GitHub private vulnerability reporting on github.com/comuvia/comuvia-sdk. If you cannot use GitHub, use the fallback address given in the repository’s SECURITY.md with a subject beginning “Security”; reports sent there are read manually, and no response-time guarantee is made. Provide a minimal synthetic reproducer; do not include credentials or private source data. This page does not send a report for you.
The repository's SECURITY.md is the policy of record. A response-time or fix-time SLA has not been established. The 0.1.x alpha line is the policy's supported version family.