Files
docs/security/data-leak-audit-2026-05-21-tr004-artifacts/index.html
T

2273 lines
44 KiB
HTML

<!doctype html>
<html lang="en" class="no-js">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="description" content="Single source of truth for the homelab">
<link rel="canonical" href="http://192.168.1.8:13080/security/data-leak-audit-2026-05-21-tr004-artifacts/">
<link rel="prev" href="../data-leak-audit-2026-05-20-tr004-cloud-sandbox/">
<link rel="next" href="../audit-claude-code-meta/">
<link rel="icon" href="../../assets/images/favicon.png">
<meta name="generator" content="mkdocs-1.6.1, mkdocs-material-9.7.6">
<title>2026-05-21 · artifacts (clean) - nuclide.systems docs</title>
<link rel="stylesheet" href="../../assets/stylesheets/main.484c7ddc.min.css">
<link rel="stylesheet" href="../../assets/stylesheets/palette.ab4e12ef.min.css">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
<style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
<script>__md_scope=new URL("../..",location),__md_hash=e=>[...e].reduce(((e,_)=>(e<<5)-e+_.charCodeAt(0)),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
</head>
<body dir="ltr" data-md-color-scheme="slate" data-md-color-primary="black" data-md-color-accent="blue">
<input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
<input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
<label class="md-overlay" for="__drawer"></label>
<div data-md-component="skip">
<a href="#data-leak-audit-2026-05-21-analyzing-lumen-tr004-test-data" class="md-skip">
Skip to content
</a>
</div>
<div data-md-component="announce">
</div>
<header class="md-header" data-md-component="header">
<nav class="md-header__inner md-grid" aria-label="Header">
<a href="../.." title="nuclide.systems docs" class="md-header__button md-logo" aria-label="nuclide.systems docs" data-md-component="logo">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54"/></svg>
</a>
<label class="md-header__button md-icon" for="__drawer">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3zm0 5h18v2H3zm0 5h18v2H3z"/></svg>
</label>
<div class="md-header__title" data-md-component="header-title">
<div class="md-header__ellipsis">
<div class="md-header__topic">
<span class="md-ellipsis">
nuclide.systems docs
</span>
</div>
<div class="md-header__topic" data-md-component="header-topic">
<span class="md-ellipsis">
2026-05-21 · artifacts (clean)
</span>
</div>
</div>
</div>
<form class="md-header__option" data-md-component="palette">
<input class="md-option" data-md-color-media="(prefers-color-scheme: dark)" data-md-color-scheme="slate" data-md-color-primary="black" data-md-color-accent="blue" aria-hidden="true" type="radio" name="__palette" id="__palette_0">
<input class="md-option" data-md-color-media="(prefers-color-scheme: light)" data-md-color-scheme="default" data-md-color-primary="black" data-md-color-accent="blue" aria-hidden="true" type="radio" name="__palette" id="__palette_1">
</form>
<script>var palette=__md_get("__palette");if(palette&&palette.color){if("(prefers-color-scheme)"===palette.color.media){var media=matchMedia("(prefers-color-scheme: light)"),input=document.querySelector(media.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");palette.color.media=input.getAttribute("data-md-color-media"),palette.color.scheme=input.getAttribute("data-md-color-scheme"),palette.color.primary=input.getAttribute("data-md-color-primary"),palette.color.accent=input.getAttribute("data-md-color-accent")}for(var[key,value]of Object.entries(palette.color))document.body.setAttribute("data-md-color-"+key,value)}</script>
<label class="md-header__button md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
</label>
<div class="md-search" data-md-component="search" role="dialog">
<label class="md-search__overlay" for="__search"></label>
<div class="md-search__inner" role="search">
<form class="md-search__form" name="search">
<input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
<label class="md-search__icon md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11z"/></svg>
</label>
<nav class="md-search__options" aria-label="Search">
<button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12z"/></svg>
</button>
</nav>
<div class="md-search__suggest" data-md-component="search-suggest"></div>
</form>
<div class="md-search__output">
<div class="md-search__scrollwrap" tabindex="0" data-md-scrollfix>
<div class="md-search-result" data-md-component="search-result">
<div class="md-search-result__meta">
Initializing search
</div>
<ol class="md-search-result__list" role="presentation"></ol>
</div>
</div>
</div>
</div>
</div>
</nav>
</header>
<div class="md-container" data-md-component="container">
<nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
<div class="md-grid">
<ul class="md-tabs__list">
<li class="md-tabs__item">
<a href="../.." class="md-tabs__link">
Home
</a>
</li>
<li class="md-tabs__item">
<a href="../../CHANGELOG/" class="md-tabs__link">
Changelog
</a>
</li>
<li class="md-tabs__item">
<a href="../../RESUME/" class="md-tabs__link">
Resume
</a>
</li>
<li class="md-tabs__item">
<a href="../../ct-inventory/" class="md-tabs__link">
CT inventory
</a>
</li>
<li class="md-tabs__item">
<a href="../../infra/proxmox-state/" class="md-tabs__link">
Infra
</a>
</li>
<li class="md-tabs__item">
<a href="../../services/homelab-architecture/" class="md-tabs__link">
Services
</a>
</li>
<li class="md-tabs__item md-tabs__item--active">
<a href="../data-leak-audit-comparison/" class="md-tabs__link">
Security & audits
</a>
</li>
<li class="md-tabs__item">
<a href="../../ideas/stack-ideas/" class="md-tabs__link">
Ideas
</a>
</li>
<li class="md-tabs__item">
<a href="../../history/traefik-migration/" class="md-tabs__link">
History
</a>
</li>
</ul>
</div>
</nav>
<main class="md-main" data-md-component="main">
<div class="md-main__inner md-grid">
<div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
<label class="md-nav__title" for="__drawer">
<a href="../.." title="nuclide.systems docs" class="md-nav__button md-logo" aria-label="nuclide.systems docs" data-md-component="logo">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54"/></svg>
</a>
nuclide.systems docs
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../.." class="md-nav__link">
<span class="md-ellipsis">
Home
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../CHANGELOG/" class="md-nav__link">
<span class="md-ellipsis">
Changelog
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../RESUME/" class="md-nav__link">
<span class="md-ellipsis">
Resume
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../ct-inventory/" class="md-nav__link">
<span class="md-ellipsis">
CT inventory
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_5" >
<label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
<span class="md-ellipsis">
Infra
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_5">
<span class="md-nav__icon md-icon"></span>
Infra
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../infra/proxmox-state/" class="md-nav__link">
<span class="md-ellipsis">
Proxmox state
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/portmap/" class="md-nav__link">
<span class="md-ellipsis">
Port map
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/storage/" class="md-nav__link">
<span class="md-ellipsis">
Storage
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/volumes/" class="md-nav__link">
<span class="md-ellipsis">
Volumes
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/docker-networks/" class="md-nav__link">
<span class="md-ellipsis">
Docker networks
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/connection-hosts/" class="md-nav__link">
<span class="md-ellipsis">
Connection hosts
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../infra/proxmox-memory-audit/" class="md-nav__link">
<span class="md-ellipsis">
Memory audit
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6" >
<label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
<span class="md-ellipsis">
Services
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_6">
<span class="md-nav__icon md-icon"></span>
Services
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../services/homelab-architecture/" class="md-nav__link">
<span class="md-ellipsis">
Homelab architecture
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/dev-environment/" class="md-nav__link">
<span class="md-ellipsis">
Dev environment (Coder + Gitea)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/mcp-gateway/" class="md-nav__link">
<span class="md-ellipsis">
MCP gateway
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/mcp-servers/" class="md-nav__link">
<span class="md-ellipsis">
MCP servers
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/pocket-id/" class="md-nav__link">
<span class="md-ellipsis">
Pocket-ID (OIDC)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/backrest/" class="md-nav__link">
<span class="md-ellipsis">
Backrest (backups)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/databases/" class="md-nav__link">
<span class="md-ellipsis">
Databases
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/secrets-manager/" class="md-nav__link">
<span class="md-ellipsis">
Secrets manager
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/comfyui/" class="md-nav__link">
<span class="md-ellipsis">
ComfyUI
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/zoraxy/" class="md-nav__link">
<span class="md-ellipsis">
Zoraxy
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/adguard-dns/" class="md-nav__link">
<span class="md-ellipsis">
AdGuard DNS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/cloud-gpu/" class="md-nav__link">
<span class="md-ellipsis">
Cloud GPU
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/arcane/" class="md-nav__link">
<span class="md-ellipsis">
Arcane
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/doc-ingestion/" class="md-nav__link">
<span class="md-ellipsis">
Doc ingestion pipeline
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../services/llm-benchmark/" class="md-nav__link">
<span class="md-ellipsis">
LLM benchmark
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--active md-nav__item--section md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_7" checked>
<label class="md-nav__link" for="__nav_7" id="__nav_7_label" tabindex="">
<span class="md-ellipsis">
Security & audits
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_7_label" aria-expanded="true">
<label class="md-nav__title" for="__nav_7">
<span class="md-nav__icon md-icon"></span>
Security & audits
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../data-leak-audit-comparison/" class="md-nav__link">
<span class="md-ellipsis">
Comparison
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../data-leak-audit-2026-05-20-tr004-cloud-sandbox/" class="md-nav__link">
<span class="md-ellipsis">
2026-05-20 · cloud-sandbox breach
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--active">
<input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
<label class="md-nav__link md-nav__link--active" for="__toc">
<span class="md-ellipsis">
2026-05-21 · artifacts (clean)
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<a href="./" class="md-nav__link md-nav__link--active">
<span class="md-ellipsis">
2026-05-21 · artifacts (clean)
</span>
</a>
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#tldr" class="md-nav__link">
<span class="md-ellipsis">
TL;DR
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#data-flow" class="md-nav__link">
<span class="md-ellipsis">
Data flow
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#tool-channel-inventory" class="md-nav__link">
<span class="md-ellipsis">
Tool / channel inventory
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#why-picture-rendering-didnt-work" class="md-nav__link">
<span class="md-ellipsis">
Why picture rendering didn't work
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#fix-s3-as-a-data-exchange-hub" class="md-nav__link">
<span class="md-ellipsis">
Fix: S3 as a data-exchange hub
</span>
</a>
<nav class="md-nav" aria-label="Fix: S3 as a data-exchange hub">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#build-order-parallel-able-after-the-first-two" class="md-nav__link">
<span class="md-ellipsis">
Build order (parallel-able after the first two)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#criticality-matrix" class="md-nav__link">
<span class="md-ellipsis">
Criticality matrix
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#recommended-actions-ordered-with-parallelism" class="md-nav__link">
<span class="md-ellipsis">
Recommended actions (ordered, with parallelism)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="../audit-claude-code-meta/" class="md-nav__link">
<span class="md-ellipsis">
Self-audit (Claude Code)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../transcripts/audit-chat-2026-05-21/" class="md-nav__link">
<span class="md-ellipsis">
Transcript (audit session)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_8" >
<label class="md-nav__link" for="__nav_8" id="__nav_8_label" tabindex="0">
<span class="md-ellipsis">
Ideas
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_8_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_8">
<span class="md-nav__icon md-icon"></span>
Ideas
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../ideas/stack-ideas/" class="md-nav__link">
<span class="md-ellipsis">
Stack ideas
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_9" >
<label class="md-nav__link" for="__nav_9" id="__nav_9_label" tabindex="0">
<span class="md-ellipsis">
History
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_9_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_9">
<span class="md-nav__icon md-icon"></span>
History
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../history/traefik-migration/" class="md-nav__link">
<span class="md-ellipsis">
Traefik (abandoned 2026-05-16)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../history/traefik-migration-docker-labels/" class="md-nav__link">
<span class="md-ellipsis">
Traefik labels (abandoned)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../history/mcp-gateway-requirements/" class="md-nav__link">
<span class="md-ellipsis">
MCP gateway requirements (superseded)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../history/scrubbing-list-2026-05-17/" class="md-nav__link">
<span class="md-ellipsis">
Scrubbing list (2026-05-17)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../history/case-study/" class="md-nav__link">
<span class="md-ellipsis">
Case study
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#tldr" class="md-nav__link">
<span class="md-ellipsis">
TL;DR
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#data-flow" class="md-nav__link">
<span class="md-ellipsis">
Data flow
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#tool-channel-inventory" class="md-nav__link">
<span class="md-ellipsis">
Tool / channel inventory
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#why-picture-rendering-didnt-work" class="md-nav__link">
<span class="md-ellipsis">
Why picture rendering didn't work
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#fix-s3-as-a-data-exchange-hub" class="md-nav__link">
<span class="md-ellipsis">
Fix: S3 as a data-exchange hub
</span>
</a>
<nav class="md-nav" aria-label="Fix: S3 as a data-exchange hub">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#build-order-parallel-able-after-the-first-two" class="md-nav__link">
<span class="md-ellipsis">
Build order (parallel-able after the first two)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#criticality-matrix" class="md-nav__link">
<span class="md-ellipsis">
Criticality matrix
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#recommended-actions-ordered-with-parallelism" class="md-nav__link">
<span class="md-ellipsis">
Recommended actions (ordered, with parallelism)
</span>
</a>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-content" data-md-component="content">
<article class="md-content__inner md-typeset">
<h1 id="data-leak-audit-2026-05-21-analyzing-lumen-tr004-test-data">Data-leak audit — 2026-05-21 · <code>Analyzing LUMEN TR004 Test Data</code><a class="headerlink" href="#data-leak-audit-2026-05-21-analyzing-lumen-tr004-test-data" title="Permanent link">&para;</a></h1>
<p><strong>Conversation</strong>: <code>ec5fba44-Analyzing_LUMEN_TR004_Test_Data.json</code>
<strong>LobeHub session model</strong>: <code>qwen3-coder-30b-a3b-instruct</code> (19 turns) + <code>llama-3.3-70b-instruct</code> (2 turns)
<strong>Total messages</strong>: 41 (3 user · 21 assistant · 17 tool)
<strong>Auditor</strong>: agent doctrine-driven scan, 2026-05-21</p>
<h2 id="tldr">TL;DR<a class="headerlink" href="#tldr" title="Permanent link">&para;</a></h2>
<p><strong>Verdict: NO unapproved data egress. All conversation data stayed within the homelab + approved-partner perimeter.</strong></p>
<ul>
<li><strong>Zero</strong> <code>lobe-cloud-sandbox</code> calls — the breach channel from the prior day is absent. Model used LobeHub's <strong>builtin <code>Artifacts</code></strong> tool instead (SVG + interactive HTML generators) — those run in-process.</li>
<li>LLM inference went to <strong>SAIA / GWDG</strong> via LiteLLM (21 turns) — <strong>approved partner</strong>, <a href="https://docs.hpc.gwdg.de/services/ai-services/saia/index.html">DLR-vetted</a>, integrated with the DLR IdP federation. Not a leak in this context.</li>
</ul>
<p>Two off-host channels (both approved or low-risk):</p>
<ol>
<li><strong>SAIA (GWDG academic)</strong> — 21 assistant turns sent prompt + Shepard data + tool messages. ✅ approved partner.</li>
<li><strong><code>cdn.jsdelivr.net</code></strong> — Chart.js library reference in one generated HTML artifact. The HTML never rendered (see "Why pictures didn't render"), so the fetch never happened. If/when it does, it's a public-CDN library fetch, no payload data. Low risk; informational.</li>
</ol>
<p>Shepard MCP fetches and the Artifacts tool stayed on-LAN.</p>
<h2 id="data-flow">Data flow<a class="headerlink" href="#data-flow" title="Permanent link">&para;</a></h2>
<pre class="mermaid"><code>flowchart LR
user(["You · browser"]) --&gt;|HTTPS via Zoraxy| lobe["LobeHub · CT 104"]
lobe --&gt;|MCP, internal| shep[Shepard API · CT 101]
shep --&gt;|test data, lab notes| lobe
lobe --&gt;|prompt + Shepard results +&lt;br/&gt;tool messages| litellm[LiteLLM proxy · CT 104]
litellm -.-&gt;|qwen3-coder-30b-a3b-instruct&lt;br/&gt;llama-3.3-70b-instruct&lt;br/&gt;19+2 calls| saia[(SAIA / GWDG&lt;br/&gt;academic provider)]
litellm -. fallback only .- cerebras[(Cerebras)]
litellm -. fallback only .- gemini[(Gemini)]
litellm -. fallback only .- mistral[(Mistral)]
lobe --&gt;|builtin Artifacts&lt;br/&gt;generateSVG + generateInteractiveHTML| af[Artifacts plugin&lt;br/&gt;in-container]
af -.failed render.-&gt; user
af -. would have fetched if rendered .-&gt; cdn[(cdn.jsdelivr.net)]
classDef leak fill:#5a2a2a,stroke:#c44,color:#fcc
classDef ok fill:#234c2a,stroke:#4c8,color:#cfc
classDef stale stroke-dasharray:4 4,color:#888
class saia leak
class shep,lobe,litellm,user,af ok
class cerebras,gemini,mistral,cdn stale</code></pre>
<h2 id="tool-channel-inventory">Tool / channel inventory<a class="headerlink" href="#tool-channel-inventory" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Channel</th>
<th>Calls</th>
<th>Destination</th>
<th>Trust</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>shepard</code> MCP</td>
<td>9</td>
<td><code>shepard-api.nuclide.systems</code> (CT 101)</td>
<td>✅ LAN</td>
</tr>
<tr>
<td><code>Artifacts</code> builtin (<code>generateSVG</code> + <code>generateInteractiveHTML</code>)</td>
<td>5</td>
<td>In-container (broken — empty result)</td>
<td>✅ LAN</td>
</tr>
<tr>
<td><code>lobe-agent-documents</code> (<code>createDocument</code>, <code>readDocument</code>, <code>replaceDocumentContent</code>)</td>
<td>3</td>
<td>In-container</td>
<td>✅ LAN</td>
</tr>
<tr>
<td>LLM inference (<code>qwen3-coder-30b-a3b-instruct</code> + <code>llama-3.3-70b-instruct</code>)</td>
<td>21</td>
<td><strong>SAIA (GWDG)</strong> via LiteLLM</td>
<td>✅ approved partner (DLR-vetted, IdP-federated)</td>
</tr>
</tbody>
</table>
<h2 id="why-picture-rendering-didnt-work">Why picture rendering didn't work<a class="headerlink" href="#why-picture-rendering-didnt-work" title="Permanent link">&para;</a></h2>
<p>Three layered failures.</p>
<pre class="mermaid"><code>sequenceDiagram
participant M as Model (qwen3-coder)
participant T as Artifacts tool
participant U as LobeHub UI
participant B as Your browser
M-&gt;&gt;T: generateSVG(content="&lt;svg&gt;&lt;/svg&gt;")
T--&gt;&gt;M: "" (empty response)
Note over M,T: Tool result is length 0 — the SVG was&lt;br/&gt;accepted but no URL / handle came back.
M-&gt;&gt;U: markdown with relative path:&lt;br/&gt;![Timeline](timeline_view.svg)
U-&gt;&gt;B: render markdown as-is
B-&gt;&gt;U: GET /timeline_view.svg
U--&gt;&gt;B: 200 SPA index.html (catch-all route)
Note over B: "links take me to chat.nuclide.systems/"</code></pre>
<ol>
<li><strong><code>Artifacts</code> tool returns empty.</strong> Every <code>generateSVG</code> / <code>generateInteractiveHTML</code> result had <code>content</code> length 0. The plugin is supposed to register the SVG/HTML as a side-panel "artifact" that the UI surfaces inline, but it returns nothing useful to the model — so the model has no handle/URL to reference.</li>
<li><strong>Model invents relative paths.</strong> Without a real URL, the model writes markdown like <code>![Timeline](timeline_view.svg)</code> — relative paths against the SPA route, which returns <code>index.html</code> for any unknown path. That's why every "link takes you to <code>chat.nuclide.systems/</code>".</li>
<li><strong>No content store on the homelab.</strong> Even if the model asked "save this SVG to a URL", there's no integrated artifact storage today.</li>
</ol>
<p>LobeHub's <code>Artifacts</code> works in Anthropic's hosted claude.ai because of client-side inline rendering. The self-hosted version's behavior here is broken / incomplete — either a config gap or the build is newer than the artifact-render code.</p>
<h2 id="fix-s3-as-a-data-exchange-hub">Fix: S3 as a data-exchange hub<a class="headerlink" href="#fix-s3-as-a-data-exchange-hub" title="Permanent link">&para;</a></h2>
<p>You already have <strong>Garage S3</strong> on CT 104 (<code>/opt/stacks/shared-db/garage/</code>, moved to local NVMe 2026-05-19). Repurpose it as the artifact store for every AI surface.</p>
<pre class="mermaid"><code>flowchart LR
subgraph LH[CT 104 LobeHub]
model[Model + Artifacts tool]
interceptor["upload sidecar / fork:&lt;br/&gt;capture generateSVG / HTML output"]
end
subgraph S3[CT 104 Garage S3]
bucket[(chat-artifacts bucket&lt;br/&gt;public-read on /pub/* prefix)]
end
cs[("Coder workspaces&lt;br/&gt;CT 111&lt;br/&gt;S3 SDK"
)]
user(["Browser"])
zx[Zoraxy&lt;br/&gt;s3.nuclide.systems]
model --&gt;|content| interceptor
interceptor --&gt;|PUT /chat-artifacts/&lt;chatId&gt;/&lt;n&gt;.svg| bucket
interceptor --&gt;|public URL| model
model --&gt;|markdown with absolute URL| user
user --&gt;|GET| zx --&gt;|TLS+ACME| bucket
cs &lt;--&gt;|S3 SDK| bucket</code></pre>
<h3 id="build-order-parallel-able-after-the-first-two">Build order (parallel-able after the first two)<a class="headerlink" href="#build-order-parallel-able-after-the-first-two" title="Permanent link">&para;</a></h3>
<div class="highlight"><pre><span></span><code><a id="__codelineno-0-1" name="__codelineno-0-1" href="#__codelineno-0-1"></a>[no prereqs]
<a id="__codelineno-0-2" name="__codelineno-0-2" href="#__codelineno-0-2"></a>└── B. Fix s3.nuclide.systems Zoraxy route + Garage external endpoint (~30 min)
<a id="__codelineno-0-3" name="__codelineno-0-3" href="#__codelineno-0-3"></a> └── C. chat-artifacts bucket + ACL + lifecycle (~20 min)
<a id="__codelineno-0-4" name="__codelineno-0-4" href="#__codelineno-0-4"></a> ├── D. upload_artifact MCP server (CT 104 gateway, ~1 h)
<a id="__codelineno-0-5" name="__codelineno-0-5" href="#__codelineno-0-5"></a> ├── E. LobeHub Artifacts patch → S3 upload (TypeScript, ~3-4 h)
<a id="__codelineno-0-6" name="__codelineno-0-6" href="#__codelineno-0-6"></a> └── F. Coder savefig helper into dotfiles (~30 min)
</code></pre></div>
<p>D, E, F can run concurrently once C is up. Total elapsed if D+F land in parallel and E is deferred: ~2 hours wall time.</p>
<h2 id="criticality-matrix">Criticality matrix<a class="headerlink" href="#criticality-matrix" title="Permanent link">&para;</a></h2>
<table>
<thead>
<tr>
<th>Channel</th>
<th>Sensitivity</th>
<th>Likelihood</th>
<th>Trust</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>SAIA inference (via LiteLLM)</td>
<td>High</td>
<td>100%</td>
<td>✅ approved partner</td>
<td><strong>OK</strong></td>
</tr>
<tr>
<td><code>cdn.jsdelivr.net</code> (CDN libs)</td>
<td>Low</td>
<td>~Low (only when artifact renders)</td>
<td>external CDN, no payload data</td>
<td>LOW</td>
</tr>
<tr>
<td>Shepard MCP fetches</td>
<td>Internal</td>
<td>Every related chat</td>
<td>✅ LAN</td>
<td>LOW</td>
</tr>
<tr>
<td><code>Artifacts</code> plugin</td>
<td>In-container</td>
<td>100% in this chat</td>
<td>✅ LAN (just broken)</td>
<td>n/a</td>
</tr>
</tbody>
</table>
<h2 id="recommended-actions-ordered-with-parallelism">Recommended actions (ordered, with parallelism)<a class="headerlink" href="#recommended-actions-ordered-with-parallelism" title="Permanent link">&para;</a></h2>
<div class="highlight"><pre><span></span><code><a id="__codelineno-1-1" name="__codelineno-1-1" href="#__codelineno-1-1"></a>[no prereqs — start any]
<a id="__codelineno-1-2" name="__codelineno-1-2" href="#__codelineno-1-2"></a>├── A. Pin sensitive chats to a local LLM (LobeHub + LiteLLM)
<a id="__codelineno-1-3" name="__codelineno-1-3" href="#__codelineno-1-3"></a>├── B. Fix s3.nuclide.systems Zoraxy route (Zoraxy — needs operator OK)
<a id="__codelineno-1-4" name="__codelineno-1-4" href="#__codelineno-1-4"></a>│ └── C. chat-artifacts bucket + ACL + lifecycle (Garage)
<a id="__codelineno-1-5" name="__codelineno-1-5" href="#__codelineno-1-5"></a>│ ├── D. upload_artifact MCP server (CT 104 gateway)
<a id="__codelineno-1-6" name="__codelineno-1-6" href="#__codelineno-1-6"></a>│ ├── E. Fix LobeHub Artifacts to push S3 (TypeScript patch)
<a id="__codelineno-1-7" name="__codelineno-1-7" href="#__codelineno-1-7"></a>│ └── F. Coder savefig helper (dotfiles)
<a id="__codelineno-1-8" name="__codelineno-1-8" href="#__codelineno-1-8"></a>├── G. Clean stale DAYTONA_API_KEY from LobeHub (CT 104 env)
<a id="__codelineno-1-9" name="__codelineno-1-9" href="#__codelineno-1-9"></a>└── H. Egress firewall block (Cerebras / lobehub / codesandbox) (UniFi UDM)
</code></pre></div>
<p>See also: <a href="../data-leak-audit-2026-05-20-tr004-cloud-sandbox/"><code>data-leak-audit-2026-05-20-tr004-cloud-sandbox.md</code></a> for the prior session, and <a href="../data-leak-audit-comparison/"><code>data-leak-audit-comparison.md</code></a> for the side-by-side.</p>
</article>
</div>
<script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
</div>
<button type="button" class="md-top md-icon" data-md-component="top" hidden>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M13 20h-2V8l-5.5 5.5-1.42-1.42L12 4.16l7.92 7.92-1.42 1.42L13 8z"/></svg>
Back to top
</button>
</main>
<footer class="md-footer">
<div class="md-footer-meta md-typeset">
<div class="md-footer-meta__inner md-grid">
<div class="md-copyright">
Made with
<a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
Material for MkDocs
</a>
</div>
</div>
</div>
</footer>
</div>
<div class="md-dialog" data-md-component="dialog">
<div class="md-dialog__inner md-typeset"></div>
</div>
<script id="__config" type="application/json">{"annotate": null, "base": "../..", "features": ["navigation.tabs", "navigation.sections", "navigation.expand", "navigation.top", "search.highlight", "search.suggest", "content.code.copy"], "search": "../../assets/javascripts/workers/search.2c215733.min.js", "tags": null, "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}, "version": null}</script>
<script src="../../assets/javascripts/bundle.79ae519e.min.js"></script>
</body>
</html>