NAME
anvil-security - what anvil checks, how anvil is built and shipped, and how to report a vulnerability
SYNOPSIS
This page describes what anvil checks in your code, how anvil itself is built and shipped, and how to report a security issue.
Product behaviour is documented in detail at docs.eddacraft.ai. Where this page and the documentation differ, the documentation is current.
WHAT ANVIL CHECKS
anvil evaluates a proposed change on your machine, before it lands and again at the gate. The checks below ship in the current release.
Secret Detection
Scans a proposed write for credential-like tokens before it reaches the diff, and scans the change set again in the gate. Lines that could not be scanned are reported as failures, never assumed clean.
Command Safety
Destructive or unexpected shell commands issued by an agent are stopped at the intercept point when enforcement is enabled.
Anti-Pattern Scan
Known unsafe shapes in generated code are reported against a baseline of the existing repository, so new violations are surfaced and old ones are not re-litigated.
Architecture Boundaries
Layer and package import rules you define are held at save-time.
Policy
Write your own rules, including Rego policies evaluated with anvil policy eval. Evaluation is deterministic: the same input produces the same result every time.
Default Posture
By default anvil warns and exits zero. Blocking a write, or failing a check on warnings, is a choice the operator turns on.
HOW WE SECURE ANVIL
Local-First
Checks run on your machine. Source code is not uploaded to run them. Network access is used for installation, sign-in, licence refresh, updates, feedback you choose to send, and the anonymous usage beacon described below.
AI-Client Egress
Graph context shared with a connected AI client is identity-only by default: symbol names, locations and relationships, not source. Sending a source snippet requires an explicit request from the client and per-workspace consent, and ANVIL_GCTX_EGRESS=0 keeps it off regardless.
Deterministic Core
The policy engine contains no model. AI may explain a finding or propose a fix; it does not decide whether a change passes.
Signed Releases
Installer artefacts for each tagged release are signed with minisign, and the detached signatures are published alongside the release on GitHub.
Anonymous Telemetry
anvil sends a narrow anonymous usage beacon, at most once per installation per day, and only after an interactive first run has shown its notice. It never includes source, paths, command arguments, findings or free text. Turn it off with anvil telemetry off, ANVIL_TELEMETRY=off or DO_NOT_TRACK=1. The complete payload is documented here.
INFRASTRUCTURE
Hosting
The website, the documentation site and the early-access API run on Vercel.
Data
Waitlist and account records are stored in a managed Postgres database. Data in transit uses TLS; data at rest is encrypted by the database provider.
Access
Access to production systems follows least privilege.
RESPONSIBLE DISCLOSURE
If you find a security issue in anvil or in an eddacraft service, please report it to us before disclosing it publicly.
How to Report
Email security@eddacraft.ai with details of the vulnerability. Include steps to reproduce if possible.
What to Expect
- - Acknowledgement within 48 hours
- - Initial assessment within 5 business days
- - Updates as remediation progresses
- - Credit in the release notes, if you want it
Scope
In scope: the anvil CLI and daemon, web properties under *.eddacraft.ai, and the early-access API. Out of scope: third-party services, social engineering, physical attacks.
Safe Harbour
We will not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.
SEE ALSO
anvil(1), anvil-privacy(7), local data and security, anvil-terms(7)
AUTHOR
eddacraft