Skip to content

Security: brainlag/QudGym

Security

SECURITY.md

Security

This project installs a local C# scripting mod. Review the vendored and harness source before enabling Qud's "Allow scripting mods" option. The mod opens an authenticated loopback listener and can dispatch native gameplay/UI actions.

Do not commit local .env files, game assemblies, saves, logs, or exported state. The installer refuses to replace a non-harness mod directory and only writes beneath the explicitly configured QUD_USER_DIR.

The bridge must remain bound to loopback. Its generated auth token lives only in the installed mode-0600 .env; do not print it, place it in diagnostics, or reuse it outside this local harness. Reinstalling preserves the existing token unless the local .env is removed deliberately.

Report security issues privately to the repository owner rather than through a public issue.

There aren't any published security advisories