The current main branch is the supported development version.
Use GitHub private vulnerability reporting from the repository Security tab. Do not open a public issue containing credentials, tokens, private dataset paths, or a working exploit.
- The API binds to
127.0.0.1by default. Exposing it on another interface requires an explicit deployment security layer. - Google Earth Engine authentication and Cloud project selection remain operator-owned state.
- The Python worker accepts typed operations and never evaluates model-generated source code.
- Local analysis is restricted to configured roots.
- Artifact reads are restricted to the Earth workspace and job-scoped filenames.
- High-risk Pi tool calls require a short-lived approval receipt issued only after
ctx.ui.confirm(). Receipts are bound to one tool call, operation and canonical parameter hash; model-authored booleans cannot mint or reuse them. - The loopback Workbench API is an operator UI boundary, not a remotely authenticated service. Do not expose it to a network without authentication, authorization and CSRF protection.
- Agent-built adapters are declarative, versioned, fingerprinted, and live-probed. Live execution blocks unverified fingerprints unless the operator explicitly confirms the bypass.
- Local exports choose their own job directory; callers cannot provide an arbitrary output path. Scale and pixel budgets are checked before geedim starts.
- Generated skills require confirmation and cannot overwrite a skill that was not generated by ScoutPi.
- Remote tasks can be polled and cancelled; submitted exports may still be subject to provider-side timing and quota behavior.
- Browser credentials and cookies belong to the separate BrowserBridge profile and are not stored by this project.
- Agent traces store hashes, counts, durations, operation IDs and model usage by default. Raw prompt previews require
SCOUTPI_TRACE_DEBUG_TEXT=1. - Durable checkpoints persist only allowlisted runtime IDs, counters and recovery state. They do not persist prompts, arbitrary tool payloads, secrets or artifact contents, and every snapshot carries an integrity checksum.
- Context candidates are size-limited, provenance-bound, expired before use, checked for common secret patterns, and injected as lower-trust memory rather than policy. Writeback remains pending until direct UI approval and does not silently mutate a provider database.
- The Wisdom Weasel Context Provider is opt-in through operator-owned absolute paths. Query caps request/output/items/time, disables raw event candidates, rejects secret-looking text, and never enables the IME debug server's raw-text mode. Writeback is a separate opt-in and requires direct Pi UI approval, a canonical payload hash, durable staging, and the Core's privacy-aware adapter API; deterministic event tags make retries idempotent and ScoutPi never issues SQL against the Core database.
- The optional persistent Context worker is private to the extension process, accepts serialized JSONL over its own stdin, retains the same input/output caps, is killed on timeout or cancellation, closes after five idle minutes and at Pi session shutdown, and never opens a network listener.
- Pi capability discovery is read-only. Persisted source labels drop URL credentials, secret-like query material, control characters, and absolute path prefixes; catalog URLs and package commands are fixed to official Pi values and tampered profiles fail closed. ScoutPi never executes package commands, changes active tools, or fetches the package catalog in the background.
- Pi packages execute with the user's system permissions. The publishable tarball therefore contains only declared extensions, the investigation skill, deterministic runtime modules and public docs.
pnpm package:verifyrejects private/development paths and local credential patterns, validates fixed gallery metadata and peer dependencies, then boots the extracted package in an offline Pi RPC process before publication is allowed. - Browser evidence imports are restricted to real paths under configured roots, so symlinks cannot escape the allowlist. Inputs are size-limited, checked again for secret material, copied into the runtime artifact store, and bound by SHA-256. Stored payload integrity is rechecked on read, existing evidence IDs cannot be replaced with different content, and claim relations are always explicit.
earth_storyfails closed behind a deterministic evidence gate. Metrics require current-plan provenance and a completed live job; dry runs cannot support computed claims; browser claims retain canonical bindings; and adapter-declared proxy interpretation rules run before story persistence. Reports store hashes and IDs rather than source bodies.- Adapter claim rules accept only validated, bounded literal term lists. They cannot execute model-authored JavaScript, Python, regular expressions, or Earth Engine expressions. An optional model reviewer may add analysis but cannot override a blocking runtime review.
- The MCP compatibility server is local stdio only. It exposes no live run, export, registry mutation, workflow publication, or approval-issuance operation; artifacts remain job-scoped and resource reads are size-bounded.
- Durable triggers can replay only reviewed
readyworkflows whose execution kind is dry-runrun. Delegation grants are HMAC-signed, bind the complete trigger fingerprint and service identity, expire, enforce a maximum run count and cooldown, and fail closed after tampering or revocation. - Trigger events are exact-name, size-bounded inputs. Receipts persist only the event ID, payload hash and byte count; raw payloads cannot modify a workflow or become executable parameters. Exclusive run creation and supervisor leases provide restart-safe idempotency.
- The Workbench trigger approval endpoint trusts only the loopback operator boundary and never returns grant signatures. Use Pi's
/earth-trigger-approvedirectctx.ui.confirm()flow when stronger per-action human evidence is required.
Do not commit .env, Earth Engine credentials, Google application-default credentials, API keys, browser tokens, cookies, or private geospatial assets. Use environment variables and provider-native credential stores.