C1 Identity & least privilege
Minimal 0.13 / 1.00
OpenBitFun runs as the desktop user and hands that authority to its tools almost unchanged. The shell tool starts commands with the app's whole environment (only a few Tauri variables are removed), so any API tokens, cloud credentials or SSH agent sockets in the user's environment reach every command the model runs. Locally configured MCP servers inherit the full environment by default too; only MCP servers imported from other tools' config are started with a scrubbed environment. There is no scoped or per-task identity.
C2 Approval gates
Minimal 0.25 / 1.00
OpenBitFun has a well-built approval engine: per-call prompts that show the exact command or path, allow/ask/deny rules, exact-match grants for shell commands, delegated sub-agents that cannot widen the parent's limits, and Reject as a first-class answer. But the shipped default is Full Access, whose baseline is a single allow-everything rule, so no tool call ever asks a human unless the user switches modes. Even in Ask mode, project-scoped permission rules are not integrity-protected. Web fetch, web search, sub-agent tasks and skills are auto-allowed even in Ask mode.
C3 Tool & action scoping
Minimal 0.15 / 1.00
The default tool set includes an unrestricted shell, arbitrary-URL web fetch, file writes and deletes, computer use, cron scheduling and more, all enabled together. File tools canonicalise paths and flag anything outside the workspace, but that flag only feeds the approval engine, which is off by default; it is not a hard boundary. The shell takes any command string and WebFetch accepts any http(s) URL with no block on internal or metadata addresses.
C4 Code-execution isolation
Minimal 0.00 / 1.00
There is no isolation for model-generated commands. ExecCommand spawns the user's shell directly on the host (or on an SSH remote host) with the full environment, and the codebase itself says its shell analyser and process-tree helper are not sandboxes. No container, OS sandbox profile or VM backend exists. A malicious command or a workspace script run by the agent has the user's full authority.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Content from web pages, files, MCP results and imported instruction files enters the model context with no provenance limits, and nothing restricts what the agent does after reading it. In the default Full Access mode a prompt-injected session can both exfiltrate data (WebFetch to any URL, shell network access) and take irreversible actions without any human step. Even in Ask mode, WebFetch and web search are auto-allowed, leaving an unattended outbound channel.
C6 Memory, context & configuration integrity
Minimal 0.17 / 1.00
Long-term memory is off by default and project hooks are disabled by default, and MCP servers or tools imported from a repo's Claude Code/OpenCode/Codex config need explicit approval tied to their content. However, project-scoped permission configuration is not integrity-protected, and instruction files such as AGENTS.md load into context without a prompt.
C7 Third-party extensions
Minimal 0.30 / 1.00
MCP servers and tools imported from a project's Claude Code, OpenCode or Codex config need an approval tied to a hash of their definition, so a changed definition has to be approved again, and they start with a scrubbed environment. Natively configured MCP servers, by contrast, launch whatever command the user wrote (often an unpinned npx package) with the full parent environment, and configured OpenCode plugins are explicitly treated as trusted local executable input. Nothing is pinned or integrity-checked.
C8 Secrets & sensitive-data protection
Minimal 0.30 / 1.00
Subscription OAuth tokens live in the OS keyring, some config types redact secrets in debug output, diagnostic exports pass through a redaction filter, and memory transcripts are scrubbed of secrets. Provider API keys, however, are stored inline in the plaintext config file, and the shell tool passes the full environment, including any secrets, to every command. No third-party telemetry SDK was found.
C9 Audit & traceability
Minimal 0.45 / 1.00
Sessions are persisted as structured transcripts under the user's ~/.openbitfun directory, and permission requests and replies are written to a SQLite audit table that records whether the user, auto-approve or the system answered and any delegating parent session. The audit table is pruned to a per-project limit, sits where the agent's own shell can edit it, and in the default Full Access mode no permission events occur at all.
C10 Limits & kill switch
Minimal 0.23 / 1.00
Configurable limits exist, a round cap and a tool timeout, and stopping kills the command's whole process group. But both ship disabled: max_rounds defaults to 0 (unlimited) and tool_execution_timeout_secs defaults to None (wait forever). There is no token or cost cap, and the agent can create cron jobs that keep firing after the session ends.