security: require app-level vulnerability proofs
What changed, and why it matters
This commit only updates the project's security policy document (SECURITY.md). It tightens the rules for vulnerability reports by requiring proof-of-concept code that actually runs against the Cake Wallet app, and it asks contributors not to use AI-generated comments. There are no code changes, no bug fixes, and no direct security impact on the app itself.
No action required; this is a documentation/policy update. Continue normal security review processes for actual code commits.
Security signals we found
Policy change only: no executable code modified
Stricter vulnerability reporting requirements introduced
No vulnerability description, CVE, or patch present in the diff
Evidence from the diff
The diff modifies docs/SECURITY.md. It replaces a generic ‘step-by-step reproduction, ideally with a proof of concept’ requirement with a stricter rule that a working PoC must run directly against Cake Wallet in a release or locally built version. It also adds a ‘Communication expectations’ section discouraging AI-generated comments. No source code, build scripts, or configuration files are changed.
Changed components
docs/SECURITY.mdInspect captured patch +12 / −1
diff --git a/docs/SECURITY.md b/docs/SECURITY.md
index 0198e728..b92493be 100644
--- a/docs/SECURITY.md
+++ b/docs/SECURITY.md
@@ -30,13 +30,24 @@ security channel, so reports will not be missed.
### What to include
- A clear description of the issue and its security impact.
-- Step-by-step reproduction, ideally with a proof of concept.
+- A working proof of concept is required. It must run directly against Cake
+ Wallet itself, using a release build or locally built version, and demonstrate
+ the reported behavior and security impact. Standalone Python code,
+ mathematical examples, or simulations that only reproduce the theory without
+ exercising Cake Wallet do not satisfy this requirement.
+- Step-by-step reproduction instructions.
- Affected platforms (iOS, Android, macOS, Linux, Windows) and app version.
- Affected wallet types / chains, if applicable.
- Any relevant logs, addresses, or transaction IDs (for on-chain issues).
If you used AI tooling to find or write up the report, please say so.
+### Communication expectations
+
+AI should not be used to generate comments when communicating with maintainers
+and other contributors. Comments are expected to be written by humans. Comments
+that are believed to be written by AI may be moderated.
+
## Our commitment (safe harbor)
We consider security research conducted in good faith under this policy to be
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.