Skip to content

docs: add SECURITY.md - #266

Merged
tiero merged 2 commits into
masterfrom
claude/security-md-arkd-migration-f3oqer
Aug 1, 2026
Merged

tiero merged 2 commits into
masterfrom
claude/security-md-arkd-migration-f3oqer

Conversation

@tiero

@tiero tiero commented Aug 1, 2026 •

Copy link
Copy Markdown
Member

Adds the security disclosure policy, copied from the arkd repo, with the nostr DM contact removed — reports go to security@arklabs.to.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Ek8iDTwb1V7PVh1kKewSVg


Generated by Claude Code

Summary by CodeRabbit

  • Documentation
    • Added security guidance for privately reporting vulnerabilities.
    • Included security contact details, reporter acknowledgment information, and PGP key instructions for communicating sensitive information.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@tiero, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 57 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 7ac3e439-6b61-4e5d-a651-bb8aaaddd924

📥 Commits

Reviewing files that changed from the base of the PR and between b821120 and e41a2c3.

📒 Files selected for processing (1)
  • SECURITY.md

Walkthrough

SECURITY.md adds instructions for privately reporting Ark security issues. It includes reporter acknowledgment details, developer PGP key information, fingerprints, and a gpg --fetch-keys command.

Changes

Security Disclosure Guidance

Layer / File(s) Summary
Security disclosure instructions
SECURITY.md
Adds private reporting guidance, reporter acknowledgment details, developer PGP key URLs and fingerprints, and key import instructions.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the addition of the SECURITY.md security policy file.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/security-md-arkd-migration-f3oqer

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@SECURITY.md`:
- Line 5: Update the security-report acknowledgment statement in SECURITY.md so
Ark publicly thanks or acknowledges reporters only when they provide explicit
consent, avoiding any promise of automatic public recognition.
- Around line 9-18: Update the SECURITY.md PGP key table entries for Marco
Argentieri, Pietralberto Mazza, and Andrew Camilleri to publish each key’s
complete fingerprint instead of truncated values. Replace the placeholder gpg
command with a concrete key URL example and add a separate executable
fingerprint comparison step that verifies the fetched key against the published
fingerprint.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 9e71b3a8-fd46-4161-a4e0-f198cdd7f01e

📥 Commits

Reviewing files that changed from the base of the PR and between e73abf7 and b821120.

📒 Files selected for processing (1)
  • SECURITY.md

Comment thread SECURITY.md

Security is a top priority for Ark. If you discover a security issue, please bring it to our attention right away. Please DO NOT file a public issue, instead send your report privately by sending an email to <security@arklabs.to>.

Security reports are greatly appreciated and we will publicly thank you for it.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Make public acknowledgment opt-in.

Line 5 promises public thanks without reporter consent. This can reveal the reporter’s identity or the existence of a report. State that Ark will acknowledge reporters only with explicit consent.

Proposed wording
- Security reports are greatly appreciated and we will publicly thank you for it.
+ Security reports are greatly appreciated. With your explicit consent, we may publicly acknowledge your report.
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Security reports are greatly appreciated and we will publicly thank you for it.
Security reports are greatly appreciated. With your explicit consent, we may publicly acknowledge your report.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@SECURITY.md` at line 5, Update the security-report acknowledgment statement
in SECURITY.md so Ark publicly thanks or acknowledges reporters only when they
provide explicit consent, avoiding any promise of automatic public recognition.

Comment thread SECURITY.md
Comment on lines +9 to +18
| Name | PGP Public Key URL | Fingerprint |
|------|-------------|-------------|
| Marco Argentieri | [https://github.com/tiero.gpg](https://github.com/tiero.gpg) | 0F6586CE8DA12FB1 |
| Pietralberto Mazza | [https://github.com/altafan.gpg](https://github.com/altafan.gpg) | 6C7639DEA147673B |
| Andrew Camilleri | [https://github.com/Kukks.gpg](https://github.com/Kukks.gpg) | F918A46E23064E28 |

You can import a key by running the following command in your terminal and verify the fingerprint matches the one above:

```bash
gpg --fetch-keys <PGP Public Key URL>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Publish full fingerprints and an executable verification step.

Lines 11-13 contain only 16 hexadecimal characters. These values are not sufficient as full fingerprint verification targets. Publish the complete fingerprint for each key.

Line 18 also uses <PGP Public Key URL> as a shell placeholder. The command fetches a key but does not verify its fingerprint. Show a concrete URL and a separate fingerprint comparison step.

Proposed documentation change
-| Name | PGP Public Key URL | Fingerprint |
+| Name | PGP Public Key URL | Full Fingerprint |
...
-gpg --fetch-keys <PGP Public Key URL>
+gpg --fetch-keys https://github.com/tiero.gpg
+gpg --fingerprint FULL_FINGERPRINT
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@SECURITY.md` around lines 9 - 18, Update the SECURITY.md PGP key table
entries for Marco Argentieri, Pietralberto Mazza, and Andrew Camilleri to
publish each key’s complete fingerprint instead of truncated values. Replace the
placeholder gpg command with a concrete key URL example and add a separate
executable fingerprint comparison step that verifies the fetched key against the
published fingerprint.

@tiero
tiero merged commit adcb5a8 into master Aug 1, 2026
6 of 7 checks passed

@arkana-ai-bot arkana-ai-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arkana Review — docs: add SECURITY.md

Note: This PR is already merged; findings are recorded for the record and to inform follow-up issues.

No protocol-critical paths touched (no VTXO/signing/forfeit/round/exit changes). Two findings below.


FINDING 1 — Truncated PGP key IDs, not full fingerprints [medium]

SECURITY.md:11–13

| Marco Argentieri    | … | 0F6586CE8DA12FB1 |
| Pietralberto Mazza  | … | 6C7639DEA147673B |
| Andrew Camilleri    | … | F918A46E23064E28 |

All three values are 16 hex characters — 64-bit short key IDs, not PGP fingerprints (which are 40 hex characters / 160 bits). Short key IDs have a well-documented collision attack surface: the "Evil32" project (2016) demonstrated it is cheap to generate a keypair sharing any chosen short ID. A reporter following the instructions — gpg --fetch-keys <URL>, then checking the last 16 chars — could be deceived if an attacker pre-positions a colliding key.

Since the URL (github.com/tiero.gpg etc.) is the primary trust anchor here, the practical risk is lower than a pure short-ID scheme, but the document is supposed to be the authoritative verification step. Replace each value with the full 40-character fingerprint, e.g.:

gpg --with-fingerprint <key-file>
# or
gpg --fingerprint <keyid>

Same issue exists verbatim in arkd/SECURITY.md — fix both.


FINDING 2 — Other SDK repos have no SECURITY.md [low]

ts-sdk, go-sdk, and dotnet-sdk have no SECURITY.md. A researcher finding a vulnerability through any of those entry points has no documented disclosure path. Follow-up PRs mirroring this file (with the same full-fingerprint fix) to those repos would close the gap.


Non-findings / confirmed correct

  • Intentional removal of the Nostr NIP-04 DM channel (documented in PR body) — no objection.
  • gpg --fetch-keys instruction is correct syntax.
  • Email address security@arklabs.to consistent with other Ark repos.
  • No suspicious-content findings in PR title, body, or diff.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants