# Security policy ## Trust model Omarchy plugins execute unsandboxed with the current user's permissions. Jukebox therefore minimizes code inside the shared shell, avoids privilege escalation, and documents every external process and data destination. Voice audio is processed locally by the configured transcription engine. The final transcript is sent to the explicitly configured expert-intent compiler. Users must understand and approve that provider boundary before enabling remote compilation. Transcript bytes are always treated as untrusted content. Spoken or quoted phrases cannot select or persist a provider, model, transformation mode, delivery mode, or any other setting. Jukebox stores settings, recoverable review drafts, setup rollback metadata, and generated prompts only inside its XDG-owned directories. It repairs those plugin-owned directories to mode `0700` and atomically replaces private files at mode `0600`. Directory traversal and final-file access reject symbolic links. Raw drafts are removed after successful insertion/copy or after 24 hours; generated prompts expire after seven days by default. Provider adapters query only documented CLI status commands. Codex runs ephemerally with a read-only sandbox and ignored project instructions. Claude Code runs in safe mode with tools disabled and session persistence disabled. Jukebox never reads, copies, logs, or stores either provider's authentication material and never silently falls back to another model or provider. OpenRouter completion requests refuse every HTTP redirect so a bearer token is never replayed to a different URL. Response bodies are capped before JSON parsing: an oversized declared `Content-Length` fails immediately, and a response without a length is read only through the configured limit plus one sentinel byte. The default limit is 2 MiB and the configurable test/diagnostic limit cannot exceed 8 MiB. HTTP failures and malformed responses return bounded failure state without including the key or provider body. Streaming uses a mode-`0600` Unix socket inside Jukebox's mode-`0700` runtime directory. Public events contain only lifecycle state and provider output intended for the review draft; reasoning and tool events are ignored. The bridge expires after ten idle minutes. Successfully inserted, copied, or discarded sessions delete their source Voxtype meeting transcript; failed work remains recoverable for up to 24 hours. ## Sensitive data Do not include recordings, transcripts, generated prompts, credentials, API keys, tokens, clipboard contents, window titles, or private screenshots in issues or pull requests. Diagnostics must use bounded state names and error categories rather than content. ## Reporting a vulnerability Report suspected vulnerabilities privately through GitHub's **Report a vulnerability** flow in the repository Security tab. Do not open a public issue or attach sensitive reproduction data. ## Supported versions Only the latest published release is supported. Jukebox targets Omarchy 4 / Quattro.