TestCraft Engine accepts requirement text, parameter domains, constraints, and optional model output. The base combinatorics and traceability modules do not make network requests. The optional LLM factory can send acceptance-criteria text to the provider selected by the caller.
Use provider-specific environment variables or explicit secret injection. Do not place keys in source files, criteria files, prompts, generated packages, or command-line arguments. .env files are ignored by the repository. A package never records an API key in provenance.
The factory does not reuse an OpenAI key for DeepSeek or a custom endpoint. Unknown providers are rejected. Environment files are loaded only through the explicit load_environment function or the CLI --env-file option.
Before enabling an external provider, review the acceptance criteria for credentials, personal data, regulated information, and proprietary content. The default prompt path applies best-effort redaction for common key and token forms, but it cannot guarantee removal of every secret or identifying value. Use an approved endpoint, data-processing agreement, and local model when required by policy.
Model output is treated as untrusted structured data. It is parsed strictly, validated with Pydantic, checked for duplicate IDs and unknown references, and rejected when incomplete. A model response is not silently accepted as a partial suite.
Report suspected vulnerabilities through the repository's private security advisory or the maintainer's approved private channel. Include a minimal reproduction, affected version, impact, and whether real credentials or personal data were exposed. Do not include live secrets in a report.
Use isolated virtual environments, protect generated reports and feature files as project artifacts, and review model provenance and diagnostics before sharing a package. Atomic output writes and overwrite protection reduce accidental replacement of existing artifacts but do not replace filesystem permissions or backups.