C1 Identity & least privilege
Minimal 0.00 / 1.00
The CLI runs as the logged-in user and does nothing to narrow that authority. Shell commands start a login shell that inherits the full process environment, and MCP servers are launched with the full environment merged into their own settings, so every cloud, GitHub, SSH-agent or API credential the user has is available to anything the agent runs. There is no per-tool identity or authorization layer; the only control is the approval prompt scored under approval gates, which does not cover every path.
C2 Approval gates
Minimal 0.25 / 1.00
Interactive mode asks before running shell commands, writing or editing files, and calling MCP tools, and unknown tools default to asking. File edits show a real diff; the shell approval display does not always reflect exactly what will run. Choosing 'don't ask again' on one command writes a broad prefix rule such as Bash(git*) to the user's permissions file. The approval gate also does not cover every path. Read and Fetch also run unprompted, and there are no file checkpoints to undo damage.
C3 Tool & action scoping
Minimal 0.20 / 1.00
The default tool set includes an arbitrary shell, arbitrary-URL fetch, and file read/write anywhere on disk. Argument checks are denylists: a list of always-blocked shell commands and a list of secret-looking file names that Read and Edit refuse. Read has no workspace containment, and Fetch accepts any URL including localhost and cloud metadata addresses. Tools can be excluded or a read-only plan mode chosen, but the default enables everything.
C4 Code-execution isolation
Minimal 0.00 / 1.00
There is no execution isolation. Shell commands and MCP stdio servers all run directly on the host as the user, with the full environment, network and home directory available. No sandbox, container or OS profile exists anywhere in the CLI.
C5 Untrusted input blast radius
Minimal 0.25 / 1.00
Fetched web pages, file contents, MCP results and repository instruction files all enter the model's context with the same standing as the user's request; nothing tracks where content came from. The general approval prompt still stands in front of shell, writes and MCP calls, but it is not tied to whether untrusted content was read, and Read and Fetch run unprompted, which is enough to read a file and send it to an attacker's URL. The approval gate also does not cover every path, so a hijacked session can both exfiltrate and take irreversible action with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.25 / 1.00
The CLI has no long-term memory store, and its permissions and main config come only from the user's home directory or explicit flags. But it silently loads AGENTS.md/CLAUDE.md and .continue/rules from the working directory into the system prompt, and repository content can influence execution without any trust prompt. Project-level hook files are parsed but never executed at this commit. Saved sessions live in ~/.continue/sessions and are only reused on explicit --resume.
C7 Third-party extensions
Minimal 0.23 / 1.00
Third-party code enters as MCP servers the user adds to ~/.continue/config.yaml or passes with --mcp; the CLI does not load MCP configuration from the workspace. Server commands run exactly as configured with no version pinning or integrity check, and stdio servers are launched with the user's full environment merged in. MCP tool calls go through the approval prompt by default.
C8 Secrets & sensitive-data protection
Minimal 0.25 / 1.00
Read and Edit refuse a built-in list of secret-looking files (.env, keys, .aws/, .ssh/); the matching does not cover every path, and the check does not apply to Bash. Subprocesses inherit the full environment. Telemetry is metrics-only and off unless OpenTelemetry is configured, and logs default to info level, but session transcripts with full tool output are stored in plaintext in ~/.continue/sessions and there is no redaction anywhere.
C9 Audit & traceability
Minimal 0.45 / 1.00
Each session is saved as a structured JSON transcript in ~/.continue/sessions that records tool calls, their arguments, results and status, including denials. It is written by the agent process itself in a location its own tools can modify, carries no actor attribution or tamper evidence, and save failures are only logged. Sub-agent runs temporarily disable the history service, so their tool calls are not recorded individually.
C10 Limits & kill switch
Minimal 0.20 / 1.00
The agent loop is an unbounded while(true) with no step, wall-clock or cost limit. Shell commands have an idle timeout of 180 seconds that resets whenever output appears, and the model can raise it to 600 seconds per call; background jobs are capped at five. Pressing Escape aborts the model stream cooperatively, but a running shell command is not tied to that abort signal.