SELF-HOSTED AI GATEWAY / SECURITY EVIDENCE

Twenty-three attacks, one run, no credentials

The repository ships a regression that boots the real gateway HTTP server and then attacks it. This page is the output of that run, reformatted - every row below is a line the tool printed. The content was generated from the run rather than typed, so a row cannot quietly disagree with the tool that produced it.

23 probes · all defended · exit 0 · commit c8351472 · v25.8.1 · win32 Microsoft Windows [�汾 10.0.19045.6466 · 2026-09-26T08:45:18Z

SECTION 01 / WHAT RAN

Not a unit test

SECTION 02 / THE 23 RESULTS

What was attempted, and what came back

AttackObserved responseVerdict
A0 public enterprise health hides storage pathsstatus=200defended
A1 seed—defended
A1 cross-tenant exact-cache isolationtenant B served by a fresh provider call, never tenant A's cache lanedefended
A2 tenant header forgerystatus=403defended
A2b admin tenant header forgerystatus=403defended
A2c admin cross-tenant virtual-key creationstatus=403defended
A2d cross-tenant audit filterstatus=403defended
A2e cross-tenant global provider mutationstatus=403defended
A2f statement body cannot select another tenantstatus=400defended
A3 viewer-role key on chatstatus=403defended
A4 viewer-role key on admin surfacestatus=403defended
A4b viewer-role key on statement reconciliationstatus=403defended
A5 budget exhaustion enforced (429)—defended
A5b rate limit enforced (429)—defended
A6 cross-tenant key revokestatus=403defended
A7 secret-like text never cachedno cache marker on second calldefended
A8 anonymous /mcp/toolsstatus=401defended
A8b viewer on /mcp/toolsstatus=403defended
A8c unknown upstream rejectedstatus=400defended
A9 oversized mcp arguments rejectedcode=MCP_UPSTREAM_UNKNOWNdefended
A10 revoked key instant invalidationrevoke=200 chat=401defended
A11 /metrics requires authstatus=401defended
A11b /metrics has no secret materialstatus=200defended

The tool's own final line for this run was SECURITY AUDIT: ALL DEFENDED.

Read the list as a shape rather than a scoreboard: the recurring theme is tenant and role boundaries (a header carrying someone else's tenant, a viewer-role key on an admin surface, a cross-tenant cache or audit filter, a revoked key replaying), plus two things small gateways usually get wrong - what lands in the response cache when a prompt contains something secret-looking, and whether the metrics endpoint leaks material it authenticated everything else to protect.

SECTION 03 / RUN IT

Reproduce on any machine with Node

git clone --depth 1 https://github.com/happy520ai/unified-ai-system.git
cd unified-ai-system
pnpm install --frozen-lockfile
node tools/security-attack-regression.mjs

Expect one printed line per attack and the audit line at the end. No API key, no Docker, no account.

SECTION 04 / BOUNDARY

What this does not establish