- Never commit integration tokens to git.
- Keep runtime secrets in environment variables or local-only files.
Recommended env vars:
BIZ_NOTION_TOKENBIZ_NOTION_INVOICE_DB_ID
config.yamlis local-only and ignored by git.
- Notion mutations are disabled unless explicitly enabled:
invoice.allow_notion_mutations: false
- Mutating create calls require explicit confirmation:
invoice.require_mutation_confirm: true- CLI:
invoice create ... --upload-notion --confirm
- Render hardening:
invoice.renderer_disable_javascript: trueinvoice.renderer_no_sandbox: falseinvoice.max_render_html_bytes: 1048576
- Local artifact hardening:
- output files are written with
0600permissions - idempotency store is written with
0600and parent dir0700
- output files are written with
- optional path boundary via
invoice.output_base_dir
- Agent constraints are config-driven under
agent_policyand apply only for--actor agent. - Controls supported:
- command allowlist (
allowed_commands) - invoice ID regex guard (
invoice_id_regex) - maximum list batch size (
max_list_limit)
- command allowlist (
audit.enabledactivates append-only JSONL events with hash chaining:- each event stores
prev_hash->hash - each hash is HMAC-signed with
audit.signing_key
- each event stores
- Recommended:
- keep
audit.strict: true - store
audit.signing_keyin env/secret manager, not committed files - restrict file perms (
dir_perm: 0700,file_perm: 0600)
- keep
If you discover a security issue, open a private report with steps to reproduce and potential impact.