Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Overview · Targetly-Labs/flowllm · GitHub
Skip to content

Security: Targetly-Labs/flowllm

Security

SECURITY.md

🔒 Security Guidelines for FlowLLM

⚠️ IMPORTANT: This is a PUBLIC repository

NEVER commit API keys, secrets, or sensitive data to this repository!


🛡️ Protected Files (Already in .gitignore)

The following files are automatically excluded from git:

  • .env - All environment files
  • .env.* - Any environment variant
  • *secret* - Any file with "secret" in the name
  • *key*.json - Any JSON file with "key" in the name
  • node_modules/ - Dependencies

🔑 How to Store API Keys Safely

1. Use Environment Variables (Recommended)

Create a .env file in the root or examples directory:

# .env (THIS FILE IS IN .gitignore)
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-...
GOOGLE_API_KEY=AIza...

Load in your code:

import'dotenv/config';// or require('dotenv').config();constagent=defineAgent({provider: openai('gpt-4o'),// API key loaded from process.env});

2. Never Hardcode Keys

NEVER DO THIS:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: 'your-openai-api-key-here'// NEVER!}),});

DO THIS INSTEAD:

constagent=defineAgent({provider: openai('gpt-4o',{apiKey: process.env.OPENAI_API_KEY}),});

🔍 Before Committing - Checklist

Run this checklist BEFORE every commit:

# 1. Check for accidentally committed secrets
git grep -i "sk-proj"# OpenAI keys
git grep -i "sk-ant"# Anthropic keys
git grep -i "AIza"# Google keys# 2. Check .env files
git status | grep ".env"# Should show nothing# 3. Review staged files
git diff --staged
# 4. Use git-secrets (optional but recommended)
git secrets --scan

🚨 If You Accidentally Commit a Key

Act immediately:

  1. Revoke the key at the provider's dashboard
  2. Remove from git history:
    git filter-branch --force --index-filter \
    "git rm --cached --ignore-unmatch PATH/TO/FILE" \
    --prune-empty --tag-name-filter cat -- --all
  3. Force push (if already pushed):
    git push origin --force --all
  4. Generate new keys and update your .env file

🛠️ Recommended Security Tools

1. git-secrets

Prevent committing secrets:

# Install
brew install git-secrets # macOS# or
git clone https://github.com/awslabs/git-secrets
# Setup
git secrets --install
git secrets --register-aws # If using AWS
git secrets --add 'sk-[Pp]roj-[A-Za-z0-9]{32,}'# OpenAI pattern
git secrets --add 'sk-ant-[A-Za-z0-9]{32,}'# Anthropic
git secrets --add 'AIza[A-Za-z0-9_-]{35}'# Google

2. Pre-commit Hooks

Create .git/hooks/pre-commit:

#!/bin/bash# Check for common secret patternsif git grep -qE '(sk-[Pp]roj-|sk-[Aa]nt-|AIza)'$(git diff --cached --name-only);thenecho"❌ ERROR: Potential API key found in staged files!"echo"Please remove API keys before committing."exit 1
fi# Check for .env files (except .env.example)if git diff --cached --name-only | grep -qE '^\.env($|\.(?!example))';thenecho"❌ ERROR: .env file in staged changes!"echo"Make sure .env is in .gitignore"exit 1
fiecho"✅ Pre-commit checks passed"exit 0

Make it executable:

chmod +x .git/hooks/pre-commit

📝 Environment File Examples

Development (.env)

# Local development - NEVER COMMIT THIS FILE
OPENAI_API_KEY=your-openai-api-key-here
ANTHROPIC_API_KEY=sk-ant-your-real-key-here
GOOGLE_API_KEY=AIza-your-real-key-here

Template (.env.example)

# Template - SAFE TO COMMIT
OPENAI_API_KEY=your_openai_api_key_here
ANTHROPIC_API_KEY=your_anthropic_api_key_here
GOOGLE_API_KEY=your_google_api_key_here

🔐 Additional Security Best Practices

1. Use Key Restrictions

Configure API key restrictions at provider dashboards:

  • OpenAI: Set rate limits, allowed models
  • Anthropic: Set usage limits
  • Google: Restrict by IP, HTTP referrer

2. Rotate Keys Regularly

  • Change API keys every 90 days
  • Revoke old keys immediately after rotation

3. Monitor Usage

  • Set up billing alerts
  • Monitor for unusual activity
  • Review API usage regularly

4. Development vs Production Keys

  • Use separate keys for dev and prod
  • Set lower limits on dev keys
  • Never use production keys in examples

5. Team Collaboration

  • Use a secrets manager (1Password, LastPass, AWS Secrets Manager)
  • Never share keys via Slack, email, or chat
  • Use environment-specific keys

📋 CI/CD Security

For GitHub Actions or other CI/CD:

# .github/workflows/test.ymlname: Teston: [push, pull_request]jobs:
test:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3# Store secrets in GitHub Secrets
- name: Run testsenv:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}run: npm test

Add secrets in GitHub: Repository Settings → Secrets and variables → Actions → New repository secret


✅ Quick Security Audit

Run this command to audit your repo:

# Check for any potential secrets
git log --all --full-history --source --remotes --all -- '*.env'
git log -p | grep -i "api.key\|apikey\|api_key"# Check current files
find . -name "*.env" -not -path "./node_modules/*"
grep -r "sk-proj". --exclude-dir=node_modules
grep -r "sk-ant". --exclude-dir=node_modules

🆘 Emergency Response

If a key is exposed:

  1. Revoke immediately at provider dashboard
  2. Remove from git history (see above)
  3. Generate new key
  4. Check billing for unauthorized usage
  5. Update .env with new key
  6. Document the incident

📚 Resources


Remember: Security is everyone's responsibility! 🔒

If you're unsure about something, DON'T commit it. Ask first!

There aren't any published security advisories