This repository contains the Tkach Security Strong Core, bounded Gateway, narrow real local-effect boundary, non-streaming OpenAI Responses adapter, and thin local CLI (including its terminal dashboard), HTTP, Rust/Python/Node/Go clients, and MCP stdio adapters. Reports should target bypasses of deterministic authorization, information flow, DATA/CONTROL separation, provenance/classification, secret isolation, payload-free evidence, lifecycle, parser, credential, or egress invariants.
The current source has no Streamable HTTP adapter, Anthropic adapter, streaming release API, hosted service, cloud control plane, or public internet gateway. Deployment assumptions in the product contract remain in scope when a defect crosses a documented Tkach boundary.
Do not include real credentials or protected data in issues, tests, or logs. Use fake values and a minimal reproduction. For a sensitive report, contact the project owner through the repository's private security channel when one is established.
Security-critical crates forbid unsafe_code. Changes must include regression
tests for real security defects, pass the required checks in
CONTRIBUTING.md, and avoid direct privileged bypasses.