Skip to content

Security: wufufu770/NetMind

Security

SECURITY.md

Security Policy

Threat model

NetMind is a local-first network operations tool. Understand what it can touch before you run it:

Surface Guarantee
Default mode (NETMIND_DRIVER=simulation) No device is ever contacted. All commands are recorded against an in-process simulator.
Real drivers (ssh / netconf) Commands are dry-run until NETMIND_ENABLE_REAL_COMMANDS=true is explicitly set alongside credentials.
Read-only collection collect() uses napalm/ncclient getters only; it never pushes configuration.
Write execution Always gated by SecurityChecker (allowlist + deny-keywords), dangerous commands require the approval workflow (unattended_policy=deny default) or are blocked outright.
API access Unset NETMIND_ADMIN_TOKEN = open local mode. When set, every non-GET request requires Authorization: Bearer <token>.
LLM enrichment Only structured findings JSON leaves the machine, never device configs or credentials. Responses are cached locally under ~/.cache/netmind/.

Known limitations

  • The HTTP API has no rate limiting or per-endpoint RBAC. Do not expose it to untrusted networks.
  • Rollback paths bypass the "dangerous command" gate by design (they must be able to undo changes); deny-keywords still apply.
  • Credentials live in the store as masked references: secret_ref values are redacted (***) in the persisted JSON file and in every read endpoint. Point secret_ref at your vault path; provide real secrets via environment variables at runtime.

Reporting a vulnerability

Open a security advisory rather than a public issue. Expect a response within 7 days.

There aren't any published security advisories