Docs: mention weak gateway auth tokens
This commit is contained in:
committed by
Gustavo Madeira Santana
parent
29de43d307
commit
66e33abd7b
@@ -41,7 +41,7 @@ Start with the smallest access that still works, then widen it as you gain confi
|
|||||||
|
|
||||||
- **Inbound access** (DM policies, group policies, allowlists): can strangers trigger the bot?
|
- **Inbound access** (DM policies, group policies, allowlists): can strangers trigger the bot?
|
||||||
- **Tool blast radius** (elevated tools + open rooms): could prompt injection turn into shell/file/network actions?
|
- **Tool blast radius** (elevated tools + open rooms): could prompt injection turn into shell/file/network actions?
|
||||||
- **Network exposure** (Gateway bind/auth, Tailscale Serve/Funnel).
|
- **Network exposure** (Gateway bind/auth, Tailscale Serve/Funnel, weak/short auth tokens).
|
||||||
- **Browser control exposure** (remote nodes, relay ports, remote CDP endpoints).
|
- **Browser control exposure** (remote nodes, relay ports, remote CDP endpoints).
|
||||||
- **Local disk hygiene** (permissions, symlinks, config includes, “synced folder” paths).
|
- **Local disk hygiene** (permissions, symlinks, config includes, “synced folder” paths).
|
||||||
- **Plugins** (extensions exist without an explicit allowlist).
|
- **Plugins** (extensions exist without an explicit allowlist).
|
||||||
|
|||||||
Reference in New Issue
Block a user