Intrikata Stack guide · package 1.7.1
Security policy
Security policy
Supported surfaces
| Surface | Support |
|---|---|
| https://docs.intrikata.com (Pages + Functions) | Current production |
| Skills package zip + dumb-HTTP git tree | Current package version (see MANIFEST) |
| Local install of megapraxis / metamegapraxis | Best-effort on Claude Code, Codex, Grok Build |
What this project is (security-relevant)
- Instruction skills — the portable plugin is instruction skills (megapraxis, metamegapraxis, praxis-local-realize, megametapraxis) + docs/adapters. No bundled MCP server, auth connector, or project-file writer in the Codex plugin path. Grok/Claude drift hooks install separately via
megametapraxis/scripts/install_hooks.py(user-local, not the Codex plugin). - Optional backends — Intrikata Topology /
intrikata-topologyMCP / CF operant are optional. Tier 0 filesystem-fallback is a designed valid path. - Public snapshots — scrubbed operational state only (no home paths, usernames, or full UUIDs).
Reporting a vulnerability
Please report security issues privately when possible:
- Prefer a direct message to the project operator for the deployment you are using.
- If you only have the public site, open a responsible-disclosure write-up without exploit
payloads and without exfiltrated personal data: describe impact, affected surface, and a minimal reproduction.
- Do not open a public issue with working exploit code for live ingestion endpoints.
Ingest endpoint note
POST /api/snapshots is bearer-token gated. Browser-origin writes are restricted to the canonical site; server-to-server requests may omit Origin. Bodies are capped at 128 KiB, nested snapshot fields are type- and count-validated, and write attempts are throttled to 30 requests per minute per observed edge IP. Do not attempt to brute-force tokens. If you find an auth bypass or injection path against the Pages Functions / D1 layer, report it privately.
Safe harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations and service disruption
- Do not access data belonging to other users beyond what is needed to demonstrate impact
- Report findings promptly and do not exploit them beyond proof of concept
Hardening expectations (operators)
- Rotate
INTRIKATA_INGEST_TOKENif exposed - Keep Cloudflare account MFA enabled
- Deploy production with
--branch=master - Review CSP / headers in
_headersafter any script change; the first-party inline script is
hash-pinned and inline event handlers are forbidden
- Keep API responses
no-storeand preserve their MIME, frame, referrer, and resource policies
Residual (honest)
There is no formal bug-bounty program and no guaranteed SLA on private reports. Cache API rate limiting is edge-local and best-effort rather than a globally atomic abuse counter. These are named residuals, not silent claims of enterprise support.