Security, actually done
The full report (Traditional Chinese) is SECURITY_REPORT.md in the source. Summary below.
- 🛡️ SSRFhttp(s) only; private/metadata IPs blocked; redirects and the actual socket peer re-checked (anti DNS-rebinding).
- 🗜️ Zip-slip / 路徑Extraction rejects `..`, absolute paths, symlinks and zip bombs; filenames are sanitised.
- 🎞️ ffmpegArgument lists, no shell; URLs/protocols refused as inputs; filter values allow-listed.
- 🧾 輸出HTML reports escaped + CSP; CSV/XLSX formula-injection guard; EXIF/GPS stripped on export.
- 🔑 授權Ed25519 public-key verification, private keys never shipped; honest that client checks can be patched.
- 📊 稽核pip-audit / npm audit: 0 known vulns; bandit & semgrep findings resolved; gitleaks clean; 388 tests passing.
Audit results
| pip-audit | Suite venv (136 deps), subtitle-studio (36), 3 lock files: 0 known vulnerabilities |
|---|---|
| npm audit | mockup-studio, invoice-pro, linkinbio-builder, _qa: 0 vulnerabilities |
| bandit | Initially 3 high / 4 medium / 48 low → fixed or justified inline; final 0 |
| semgrep | python / javascript / typescript / security-audit / secrets: 13 → 5 (all seller-only private keys, never in any public file or release) |
| gitleaks | No leaks in source; release archives scanned: 0 findings |
| pytest | 388 tests passing (incl. security tests) |
Issues fixed (excerpt)
- Old Gradio dashboard bound to 0.0.0.0 → new panel defaults to 127.0.0.1 and refuses public binds
- Web products embedded the HMAC secret in JS (anyone could mint keys) → Ed25519 public-key verification
- Subtitle Studio: stored XSS, CSRF / DNS rebinding, no CSP, unvalidated uploads → all fixed
- Link-in-Bio: imported project JSON could inject CSS/HTML via <style> → colour & image-source allow-lists
- sys_tools: PowerShell notification command injection → parameterised and properly quoted
- Shell time machine: unsalted SHA of secrets, leftover env files → keyed HMAC, 0600 permissions
- Zip-slip, absolute members, zip bombs; format-string injection in batch rename
- SSRF in web tools (incl. redirects & DNS rebinding); ffmpeg argument and protocol injection
- CSV/XLSX formula injection; HTML report escaping + CSP; EXIF stripped on image export
- AI model downloads pinned to revisions, safetensors only; non-commercial InsightFace model removed
Honest limits
Client-side licence checks (Ed25519 included) can still be patched out by a determined user; stronger protection needs online activation.