▲ intrikata-stack

Intrikata Stack guide · package 1.7.1

Security policy

Human-readable guide · view canonical Markdown · updated 2026-08-26

Security policy

Supported surfaces

SurfaceSupport
https://docs.intrikata.com (Pages + Functions)Current production
Skills package zip + dumb-HTTP git treeCurrent package version (see MANIFEST)
Local install of megapraxis / metamegapraxisBest-effort on Claude Code, Codex, Grok Build

What this project is (security-relevant)

Reporting a vulnerability

Please report security issues privately when possible:

  1. Prefer a direct message to the project operator for the deployment you are using.
  2. If you only have the public site, open a responsible-disclosure write-up without exploit

payloads and without exfiltrated personal data: describe impact, affected surface, and a minimal reproduction.

  1. Do not open a public issue with working exploit code for live ingestion endpoints.

Ingest endpoint note

POST /api/snapshots is bearer-token gated. Browser-origin writes are restricted to the canonical site; server-to-server requests may omit Origin. Bodies are capped at 128 KiB, nested snapshot fields are type- and count-validated, and write attempts are throttled to 30 requests per minute per observed edge IP. Do not attempt to brute-force tokens. If you find an auth bypass or injection path against the Pages Functions / D1 layer, report it privately.

Safe harbor

We will not pursue legal action against researchers who:

Hardening expectations (operators)

hash-pinned and inline event handlers are forbidden

Residual (honest)

There is no formal bug-bounty program and no guaranteed SLA on private reports. Cache API rate limiting is edge-local and best-effort rather than a globally atomic abuse counter. These are named residuals, not silent claims of enterprise support.

Intrikata Stack · MIT · current catalog: 53 operational traps · Security