Skip to content

Security: koliha/ewp

Security

SECURITY.md

Security

EWP evaluates evidence. It does not authenticate callers, sign tokens, or authorize actions.

EWP assumes source-origin metadata presented in an EvidenceView has been authenticated or established by the trusted ingestion/adapter boundary. Untrusted agents must not be permitted to self-assert trusted origin_type values. EWP prevents epistemic laundering after ingestion; it does not itself authenticate evidence entering the ledger.

What this project does not protect

  • Agent tool execution
  • Secret storage
  • Prompt injection against an MCP client. ewp.mcp_server is an ingest boundary, not an authenticator. Every write requires a server-side ingest role (--allow-ingest on stdio, the ingest token on HTTP); without it the server is evaluate-only and opens its ledger with SQLite's read-only mode, so even a bug in a tool cannot write. ingest_attestation is not a credential.
  • The HTTP façade (POST /mcp) has no TLS and no origin check. Bind it to loopback. Supply the ingest token through EWP_INGEST_TOKEN or --ingest-token-file, not the command line.
  • Caller-built evidence. An inline EvidenceView sent to ewp_warrant_now has its trusted origins demoted; ewp_may_act refuses inline views and older snapshots and decides on the latest stored evidence at server time; a caller cannot choose the decision time.
  • Store credentials

Those belong in the platform (OpenClaw allowlists, Tenuo-style action warrants, ordinary IAM).

What to report

  • A path where endogenous processing (summarization, Dreaming, majority, Graphiti invalidation) can raise verification without new external evidence
  • A path where compression or retrieval omits a contradictor without sufficiency=DEGRADED
  • A path where may_act can be skipped, inferred from WarrantView alone, or steered to older evidence or a caller-chosen time
  • A write path that changes a stored record, conflict participants, or view completeness without the ingest role
  • Invalid input that is evaluated instead of refused (a value outside a closed enum, a record about another proposition, a mistyped field, a missing required field)
  • An adapter that loses a field (subjects[], polarity, timestamps, completeness) and changes the axes on round trip
  • Supply-chain issues in this repository

Open an issue marked security or contact Rob Koliha privately if you have an unfixed write-up. There is no bug bounty attached to this release.

There aren't any published security advisories