01Purpose
CHIMERA runs autonomous agents with real tools — shell access, file access, a live browser and connected applications. This policy sets out what you must not do with it. It forms part of the Terms & Conditions.
02Prohibited uses
You must not use CHIMERA to:
- Break any applicable law, or help anyone else do so.
- Access, alter or damage any system, account or data you are not authorised to access.
- Create or distribute malware, ransomware, exploits or credential-harvesting tools.
- Conduct surveillance, stalking, harassment or doxxing of any person.
- Generate or distribute content that sexualises children, incites violence, or promotes terrorism.
- Produce disinformation at scale, impersonate real people or organisations, or manipulate elections.
- Scrape or process personal data without a lawful basis, or in breach of a site's terms.
- Infringe copyright, trade marks, trade secrets or other intellectual property.
- Make automated decisions with legal or similarly significant effects on people without meaningful human review.
03Agent-specific rules
- Do not deliberately disable, patch around or defeat the Governor, capability allowlists, egress allowlists, approval gates or loop bounds, and then run the result against systems or people who have not consented.
- Do not grant an agent broader tool access than its task requires in an environment where it could cause harm.
- Do not point browser automation at services whose terms forbid automated access.
- Do not use CHIMERA to act on behalf of another person without their informed consent.
- Use approval gates before anything irreversible — sending, publishing, deleting, transferring or paying.
04Rate limits and third parties
Agents can make many requests quickly. You are responsible for staying within the rate limits, quotas and terms of every provider and website your agents touch. The free built-in web search rate-limits under load; add your own search key in Providers rather than working around it.
05Security research
Good-faith security research on CHIMERA itself is welcome. Test only against your own installation, do not access anyone else's data, and report findings privately through the repository's security page before disclosing publicly. Reasonable time will be given to fix issues, and credit given if you want it.
06Reporting abuse
If you believe CHIMERA is being used in breach of this policy, report it at github.com/HammadM-dev/chimera/issues. Note that CHIMERA runs entirely on users' own machines and sends us nothing, so our ability to detect or intervene in misuse is inherently limited.
07Enforcement
Breaching this policy ends your permission to use CHIMERA under the Terms. Where the law requires it, breaches may be reported to the relevant authorities.