C1 Identity & least privilege
Minimal 0.25 / 1.00
Orkas runs as the logged-in OS user. In the default mode its file tools and shell can reach any path outside the workspace; only credential-like paths trigger a prompt. Shell children get a scrubbed environment (HOME, PATH, locale and Orkas paths), so model API keys are not handed to commands. External CLI agents (Claude Code, Codex, OpenClaw and others) inherit the app's full environment. No per-tool or per-request identity exists, and the narrower workspace-only mode is opt-in.
C2 Approval gates
Minimal 0.25 / 1.00
Risky shell commands, sensitive paths, out-of-workspace deletes and connector send/delete actions open a blocking dialog. The dialog fails closed when no renderer is present, and task-wide grants live only in memory. The gate is a risk classifier, not an allowlist: ordinary commands, inline Python/Node scripts that delete files, GET-based network calls and connector edits run without asking. The dialog shows only the first 800 characters of a command. Protection of the approval-mode setting is not tamper-resistant.
C3 Tool & action scoping
Minimal 0.38 / 1.00
File tools resolve paths and check them against workspace roots. write_file refuses to overwrite foreign files, connectors carry exact per-action risk tables and batch limits, and a few connector actions are blocked outright. The main tools stay general-purpose, though: bash takes any command string and web_fetch takes any URL, with no private-address block outside programmatic calls. In the default mode both reach the whole machine. The Commander can load more tool groups, including shell execution, on its own.
C4 Code-execution isolation
Minimal 0.28 / 1.00
Shell commands run as ordinary child processes of the app, under the user's account. The environment is scrubbed, but nothing isolates the filesystem or network. A macOS Seatbelt profile limiting writes to the workspace exists, but it applies only in the opt-in workspace-only mode on macOS. It still allows all reads and all network, and its enforcement is not a complete boundary. Linux and Windows have no isolation at all.
C5 Untrusted input blast radius
Minimal 0.25 / 1.00
No mechanism tracks or acts on untrusted content. Some dangerous operations always ask for approval, whatever the input source: curl/ssh-style egress, external mutations, sensitive paths, and connector sends and deletes. Others do not: web_fetch can GET any URL with data in the query string, inline Python or Node scripts are checked only for external-API writes, and script-based deletes go unflagged. Injected content can therefore both leak data and destroy files without a human.
C6 Memory, context & configuration integrity
Minimal 0.30 / 1.00
The memory tool tells the model to write durable memory on its own initiative. Entries are screened only by a short regex list for injection phrases, then frozen into the system prompt of later sessions. Agents also learn reusable skills through a skill-management tool and reflection. AGENTS.md files from the working directory up to the repository root are loaded automatically. Workspace files cannot add tools, MCP servers or approval rules. Memory is stored per user and per agent, with shared and user tiers that apply across agents.
C7 Third-party extensions
Minimal 0.30 / 1.00
Third-party additions mostly need explicit consent. A custom MCP install shows the exact command or URL. Skill imports must come from a path the user supplied, and marketplace installs are user-confirmed and version-recorded. Sources are not integrity-checked, though: marketplace integrity handling is not a complete check, and custom MCP commands run as written. Extensions run as the same OS user. MCP servers get only their configured environment, while external CLI agents inherit the full app environment.
C8 Secrets & sensitive-data protection
Moderate 0.50 / 1.00
Logs go through structured field redaction and positional secret masking, and permission logs deliberately omit command and path text. Shell children never receive provider keys in their environment. In the open-source build, stored keys and OAuth tokens are only obfuscated: the AES key comes from a constant salt in the source plus the user id, so the agent's own shell can decrypt them. Nothing redacts secrets in tool results sent to the model, and transcripts are plain JSONL. No third-party telemetry was found.
C9 Audit & traceability
Minimal 0.45 / 1.00
Each session is persisted as JSONL with tool calls and results, and persistence failures raise errors instead of passing silently. Permission requests and denials are logged with masked ids and risk categories, deliberately without command text. Records sit in the Orkas data directory. In the default mode the agent's file and shell tools can write there, and nothing chains, signs or exports the records.
C10 Limits & kill switch
Minimal 0.40 / 1.00
Each turn has a tool-round cap (100, or 120 for the Commander), a 24-hour execution deadline and a 30-minute idle watchdog, plus a 60-minute default timeout per shell command. Stopping kills the whole process group, and agent concurrency is capped at 4 per conversation. The model can pass a longer shell timeout or start background processes that outlive the conversation. There is no token or cost ceiling.