TOOLDOCK

Security model

Treat every file as untrusted

File signatures and DOCX content types are checked. Worker timeouts stop expensive jobs. Images have byte and pixel limits; PDFs have byte and page limits. ZIP packages have entry, extracted-size and individual-part limits, with streamed output bounds. XML DTDs and entities are rejected. Metadata is rendered as escaped text.

No uploaded content executes

PDF scripts are detected but never run. DOCX macros and embeddings are never executed. No document HTML is rendered and no relationship is fetched. CSP restricts connections to this origin and disallows object embedding. Parser bugs and browser resource exhaustion remain possible despite these defenses.

Responsible disclosure

A public security contact has not been configured. The deployment owner must set NEXT_PUBLIC_CONTACT_EMAIL before public launch. Do not send private files in a vulnerability report.

Check a file →