NEXUS adheres to strict security and privacy standards:
- Zero Hardcoded Secrets: No API keys, credentials, tokens, or private metadata are stored in source code.
- Environment & Registry Precedence: Sensitive API keys (
GEMINI_API_KEY,OPENAI_API_KEY) are read strictly from OS environment variables or secure local registry stores (HKCU\Environmenton Windows). - Log Sanitization: All sensitive credentials detected in stderr, stdout, or HTTP error bodies are automatically scrubbed and redacted to
[REDACTED_API_KEY]. - Path Traversal Protection: BUBU and NEXUS strictly validate file boundaries, ensuring file arguments resolve within designated project trees to prevent unauthorized filesystem read/write operations.
- Circuit Breaking for Freeze & Loop Lockout: Repeated identical requests and rapid cycling visual triggers are automatically halted by deterministic circuit breakers to prevent token drain and runaway loops.
If you discover a potential security defect, credential leak risk, or path traversal vulnerability in NEXUS:
- Please report it responsibly via GitHub Security Advisories at https://github.com/aethelondev-stack/NEXUS/security/advisories.
- Do NOT open public issues containing sensitive vulnerability details or proof-of-concept exploits.
- Security reports will be reviewed and addressed promptly by the maintainers.