Report privately through GitHub: Security → Report a vulnerability on this repository. That opens a draft advisory only you and the maintainer can read.
Please do not open a public issue for a suspected vulnerability. If GitHub's private reporting is unavailable to you, email the address on the maintainer's commits instead.
A useful report says what an attacker gets, and how to reproduce it. A patch is welcome but never required.
This is a single-maintainer project. Expect an acknowledgement within a week rather than within a day, and no bounty.
Only the latest tagged release. mininaru is pre-1.0 and fixes land on master
and in the next tag rather than as backports.
These are bugs. Report them.
- Reaching any
/api/v1endpoint without a valid bearer token, or learning whether a guessed key was close. - Escaping the working directory from
file_read,file_write, orbash_exec— anything that makes the root inmodules/file/file.gonot hold. - Running a
dangeroustool without the approval gate outside an explicitly trusted directory — a/yolomode ofoff(the default) orpersistoutside its anchor still auto-running a call, or a-prun executing a dangerous tool instead of denying it. This includes prompt injection that defeats the gate, as opposed to injection that merely asks for a tool. - A provider API key or
MININARU_API_KEYappearing in logs, terminal output, an API response, or an error message. - Any data from one API request surfacing in another.
serveis stateless and keeps no conversation between requests, so leakage across them is a bug.
These are documented, deliberate behaviour. A report about them will be closed with a pointer here.
bash_execruns shell commands andfile_writewrites files. That is what the tools are. In the chat client each dangerous call is gated by an approval prompt unless the directory is trusted via/yolo persist/on, and-pdenies them outright because nobody is there to approve.- Provider keys are stored unencrypted in
provider.json, written at mode0600inside a0700data directory. They are masked in list output, not protected at rest. Anyone who can read your home directory can read them. - Configuring an MCP server runs a program.
mcp add --stdio <command>means that command is launched on the next run. Adding one is equivalent to running it yourself. - A model asking to do something harmful is expected. The approval gate, the permission tiers, and the working-directory root are the controls. Report a way past those, not the request itself.
- Anyone who can write to the data directory controls the agent — its system prompt, its skills, its MCP servers. The directory is the trust boundary.
servebinds127.0.0.1by default and has no TLS. Exposing it with--host 0.0.0.0puts a bearer token on the wire in plaintext; terminate TLS in front of it.