C1 Identity & least privilege
Minimal 0.00 / 1.00
Every teammate runtime runs as the desktop user with the app's full process environment merged with the user's interactive-shell environment, so cloud CLIs, SSH agents, gh tokens and provider API keys are all reachable. There is no scoped identity or per-request authorization layer between the agent and those credentials. Team-launch control paths are not locked down. A hijacked teammate holds the user's whole account across services.
C2 Approval gates
Minimal 0.25 / 1.00
Teams launch with Claude's permission prompts disabled by default: the 'auto-approve tools' toggle starts on, and the app passes --dangerously-skip-permissions with bypassPermissions to the lead, every teammate and scheduled runs. An approval mode exists when the user unticks it; it routes each tool request to an in-app sheet that shows the exact command, JSON input and a diff. Even in that mode the app writes allow rules for Edit, Write and NotebookEdit into the project's .claude/settings.local.json, and an 'allow all' button flips the team to auto-approve. File changes can be rejected afterwards through the review panel, but shell side effects cannot.
C3 Tool & action scoping
Minimal 0.07 / 1.00
The consequential tools are the runtime's own general-purpose ones (Bash, Write, WebFetch), passed through with no argument validation added by this project. The app's own MCP tools for tasks, messages and kanban use typed zod schemas and check that the team exists, but they take model-chosen file paths and directories. The default tool set includes shell, write and network; the app removes only a few orchestration tools (team launch and stop, TeamDelete). A misused tool can reach the whole machine.
C4 Code-execution isolation
Minimal 0.15 / 1.00
No sandbox of any kind wraps the runtimes the app launches: no container, OS sandbox profile or seccomp/landlock policy, and the processes run with the user's full environment. The only separation is an optional per-teammate git worktree, which is a separate working directory, not a boundary, and is off by default. Model-written commands therefore run directly on the host as the user.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Teammates read repository files, web content and messages from other agents and other teams, and nothing in the orchestration layer marks or limits that content. Because the default launch bypasses all permission prompts, an injected instruction can make a teammate exfiltrate secrets over the network and take irreversible actions such as pushing code, with no human involved. Cross-team messaging lets one team's agents instruct another team's agents. Rendered markdown is sanitized, but not on every rendering path.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
The app automatically answers the runtime's 'trust this folder' prompt and its bypass-permissions warning by sending keystrokes to the terminal, and pre-marks Codex projects as trusted. That removes the user decision that normally gates a repository's own settings, hooks, MCP servers and instruction files. Team tasks, comments and messages persist on disk and are re-injected into teammates' context in later sessions, with no provenance or review. Agents can also write into other teams' inboxes.
C7 Third-party extensions
Minimal 0.13 / 1.00
MCP servers installed from the app's catalog run via 'npx -y' with the registry-supplied version when there is one and the latest package otherwise, with no integrity check. The user chooses each install explicitly, but project-scope MCP servers from the repository still load through the runtime's native settings once the app has auto-accepted workspace trust. Every MCP server runs as the user with the full environment.
C8 Secrets & sensitive-data protection
Minimal 0.28 / 1.00
Provider API keys that the app manages are encrypted at rest through the OS keychain, and Sentry error reports pass through a redaction filter for tokens, emails and keys. Those keys are then placed in the runtime's environment together with the user's entire shell environment, where any teammate can print them with Bash, and nothing redacts what goes to the model. Sentry crash reporting is on by default unless the user turns telemetry off. Runtime stdout/stderr logs are written with owner-only permissions but not redacted.
C9 Audit & traceability
Minimal 0.45 / 1.00
Each teammate's actions are recorded in the runtime's structured session transcript under ~/.claude/projects, which the app parses to show per-task tool calls, and the app writes per-member stdout and stderr logs with owner-only permissions. Approval decisions are not durably recorded by the app, and the records sit in the user's home directory where the agent, running unsandboxed as that user, can rewrite them. Writing is best-effort with no fail-closed behaviour.
C10 Limits & kill switch
Minimal 0.15 / 1.00
Interactive teams, the main mode, launch with no turn, time or spend cap; the monthly token and cost budgets only raise alerts at 80% and 100%. Scheduled runs are better bounded, with a 50-turn default and an optional dollar cap passed to the runtime. Stopping a team kills the tracked CLI process trees, including a SIGKILL sweep, but background services that agents register are a separate list.