Security boundary: outbound network access is restricted to these domains only. If a link redirects to a non-allowlisted domain, do not follow it.
- Prefer HTTPS.
- Read-only research: GET/HEAD only (no posting credentials, no uploading repo content).
- No authentication tokens may be pasted into URLs or headers.
- If a needed domain is missing, stop and request human approval to add it (domain + rationale).
- duckduckgo.com
- bing.com
- google.com
- scholar.google.com
- github.com
- raw.githubusercontent.com
- api.github.com
- gitlab.com
- bitbucket.org
- codeberg.org
- arxiv.org
- openreview.net
- semanticscholar.org
- aclanthology.org
- proceedings.mlr.press
- jmlr.org
- docs.python.org
- developer.mozilla.org
- rfc-editor.org
- tree-sitter.github.io
- hub.docker.com
- quay.io
- huggingface.co
- pypi.org
- files.pythonhosted.org
- crates.io
- docs.rs
- npmjs.com
- registry.npmjs.org
- nuget.org
- rubygems.org
- packagist.org
- conda-forge.org
- anaconda.org
- osv.dev
- nvd.nist.gov
- cve.org
- github.com