3.8 KiB
Static Privacy and Network Review
Date: 2026-09-01
Scope: Source/config/documentation review only. Runtime capture is still required in Phase 0B.
Target rule
The final v1 should be able to operate with Internet access physically blocked, with ordinary story data traveling only:
Browser -> local application -> local Ollama
Future media should similarly use explicitly configured local providers.
AI-DnD
Static positives
- documented local single-user mode,
- local SQLite,
- local Ollama support,
- no auth required in local mode,
- hosted analytics are first-party application functionality rather than a required third-party browser tracker.
Unwanted surfaces to remove
- OpenRouter/OpenAI/Groq/vLLM provider support,
- hosted account/guest flows,
- demo API keys,
- Render deployment,
- Neon/Postgres cloud deployment path,
- visit analytics,
- QuickJS user scripting,
- Claude CLI shim if not wanted,
- any hosted-mode rate-limit/account code that adds no local value.
Risk
The cloud/hosted code is explicit and documented, which is good, but Phase 0B must prove it can be removed cleanly.
Open Dungeon
Static positives
- Ollama loopback default,
- local SQLite,
- local image backend,
- no telemetry requirement apparent in inspected package/config.
Unwanted or optional surfaces
- OpenRouter configuration,
- arbitrary remote OpenAI-compatible endpoint support,
- Tailscale/LAN exposure options,
- any runtime remote assets,
- any model/image automatic download behavior after setup.
Risk
The app is smaller, so hardening may be easier, but no runtime capture has been performed.
ai-adventure
Static positives
This project most closely matches the target from the outset:
- no telemetry,
- no cloud account,
- no MCP,
- no executable plugins,
- no shell tools,
- loopback model endpoint default,
- non-loopback warning,
- imported content treated as bounded data,
- path traversal/symlink defenses documented.
Unwanted surface
- configurable non-loopback model endpoint should be prohibited or strongly gated in the target v1.
- LM Studio provider should be replaced/extended with Ollama.
Reference projects
Gamentic
Local defaults are strong, but the project intentionally supports cloud text/image/audio dialects as alternatives. A target fork would need those disabled. Its Docker/media stack also has setup-time model acquisition concerns separate from story-time privacy.
Chronicler
Supports local Ollama but also broader providers and a separate local YantrikDB/MCP memory service. More moving parts than needed.
Sonder / Corvus
Both support local backends but also remote provider configurations; Sonder additionally has extension/optional external-service surfaces.
aiMultiFool
Primarily local, but direct code reuse is constrained by GPL considerations and it is not a fork finalist.
Required Phase 0B runtime tests
For each finalist:
- block outbound Internet access,
- start the app,
- create/load a story,
- generate multiple turns,
- trigger summarization/memory,
- trigger embeddings where applicable,
- save/restore/branch,
- for Open Dungeon, generate a local image,
- capture socket/DNS/HTTP activity,
- fail the test if story content leaves loopback or explicitly approved LAN endpoints.
Record:
- process,
- destination IP/hostname,
- port,
- trigger,
- payload classification,
- whether required or optional.
Recommended production hardening
- bind app and Ollama to loopback by default,
- allowlist provider URLs rather than accept arbitrary URLs,
- no API-key UI in v1,
- no remote URL ingestion,
- no executable campaign scripts,
- no third-party analytics,
- bundle frontend assets locally,
- content-security policy that rejects remote scripts/styles/images by default,
- CI test or integration harness that runs with outbound networking disabled.