Huntsman Agent Privacy Architecture
Native macOS security reconnaissance, evidence-cited threat intelligence, and zero-telemetry operational mandate.
[01 // LOCAL-FIRST PARSING & RECON ENGINE]
Huntsman Agent was engineered from inception around 100% on-device execution. When assessing target applications, source codebases, or authorized web endpoints:
- Local AST & File Analysis: Target parsing, tokenization, dependency mapping, and vulnerability pattern matching run entirely on your Mac's CPU/GPU cores.
- No Code Uploads: Huntsman never uploads full repositories, source dumps, or bulk file contents to any remote cloud service or central Oni X server.
- Air-Gapped Operation: Core static analysis, secret scans, and evidence compilation operate without an active internet connection.
[02 // MACOS KEYCHAIN ISOLATION]
Huntsman Agent uses the macOS operating system's native hardware-backed security enclave (Keychain Services) for all sensitive provider credentials:
› PLAINTEXT ON DISK: NEVER WRITTEN
› ACCESS CONTROL: Sandboxed application-signature locked
Your API keys (OpenAI, Anthropic, Gemini, OpenRouter) are never written to unencrypted configuration files, terminal logs, application plists, or diagnostic dumps.
[03 // SECRET REDACTION & PROMPT MINIMIZATION]
Before Huntsman Talker synthesizes conversational threat intelligence with an external LLM provider:
- Automated Pre-Flight Scrub: Hardcoded private keys, passwords, bearer tokens, API secrets, and environment variables are stripped and replaced with deterministic redaction tokens (e.g.
[REDACTED_API_KEY]). - Evidence-Only Context: Only targeted snippets demonstrating proof-of-vulnerability are assembled into prompt context—never entire source directories.
- Direct Egress Only: Network calls route directly from your Mac to your configured LLM endpoint over TLS 1.3. Oni X operates zero middleman proxies.
[04 // OPERATOR AUTHORIZATION GUARD]
Huntsman enforces defensive ethical standards. Reconnaissance sweeps require explicit operator confirmation of target ownership or authorized penetration testing engagement before scanning hooks are initialized.
[05 // CONTACT & INQUIRIES]
For security audits or vulnerability inquiries regarding Huntsman Agent:
Direct Contact: Contact@oni-x.org