Bandit
0 high / 0 medium findings across 79,334 lines in the exact release package.
Get Pro $24.50
SpiritBox Security documents local-service boundaries, optional external connections, scoped Bandit and Trivy scan evidence, known limits, and the vulnerability-reporting pathway without claiming certification or guaranteed safety.
SpiritBox is designed around local services, separated execution roles, and user-controlled data. Those design choices reduce some risks; they do not justify an absolute guarantee.
0 high / 0 medium findings across 79,334 lines in the exact release package.
0 high/critical dependency vulnerabilities in the exact packaged filesystem.
0 detected secrets in the exact release package.
Reasoning, execution, storage, search, automation, and voice services have distinct roles. Package preparation excludes runtime data and internal material, while the app exposes settings for optional integrations.
Core inference and storage are intended to run locally. Model downloads, software updates, web search, Telegram, remote ComfyUI, external APIs, and other optional integrations can communicate with third parties when enabled. Their behaviour depends on those services and your configuration.
The scans are scoped to the packaged filesystem. They are not a formal independent audit, a guarantee of exploit absence, or proof that every upstream runtime image has zero known vulnerabilities. The release record documents accepted upstream-image exceptions.
Report a suspected issue through the Support page. Do not include active credentials, private keys, customer data, or exploit payloads in an initial message.