BoundBench

Forge (forgecode)

Terminal coding agent CLI (Rust) with interactive TUI, one-shot mode and a zsh plugin, supporting many model providers, MCP servers, custom agents and skills.

github.com/tailcallhq/forgecode · 2026-10-05 · 8eb3e24

Defense-in-depth score

1.9 / 10

Minimal

As shipped, Forge runs every shell command, file change and web request the model chooses on your machine with your full permissions and environment, without asking first. There is no sandbox, and the opt-in restricted mode allows everything until you write your own rules. Content read from the web, the repository or MCP servers can therefore steer it to leak credentials and make irreversible changes, and opening an untrusted repository can change its configuration and agent behaviour. Telemetry in release builds also sends prompt text to a third party by default.

Key gaps (6)

  1. Shell commands run on the host as the user with the full inherited environment, so any credential the user holds is in reach. C1 · Identity & least privilege
  2. The permission rules for the opt-in approval mode can be rewritten by the agent's own tools and are re-read on every check. C2 · Approval gates
  3. There is no execution sandbox; model-written commands and MCP servers run directly on the host. C4 · Code-execution isolation
  4. A hijacked session can exfiltrate data with fetch or the shell and take irreversible actions, all without a human. C5 · Untrusted input blast radius
  5. Workspace `.env` files, AGENTS.md and `.forge/agents` load without a trust decision and can change configuration and replace the default agent. C6 · Memory, context & configuration integrity
  6. The project-scope MCP trust decision does not hold on every path in the default configuration. C7 · Third-party extensions

Criteria

C1 Identity & least privilege

Minimal 0.00 / 1.00

Forge runs as the local user and does nothing to narrow that authority. Shell commands start from the user's own shell with the full process environment, so cloud keys, Git tokens and provider API keys present there are available to anything the model runs. There is no separate identity, scoped token or authorization layer in code. If the agent is steered into misuse, it can do whatever the user's account can do.

C2 Approval gates

Minimal 0.25 / 1.00

Out of the box Forge asks for no approval at all: shell commands, file writes and deletions, and web fetches run as soon as the model calls them. An opt-in restricted mode can ask the user before built-in tools run, but even when switched on, the shipped permission rules allow every read, write, command and URL, so the user also has to write their own rules. Commands are matched as plain text patterns, MCP tools and sub-agent calls never pass through the check, and the rules file can be rewritten by the agent's own tools. File edits made through the file tools can be undone; shell commands cannot.

C3 Tool & action scoping

Minimal 0.13 / 1.00

Forge's tools are general purpose: the shell tool takes any command string, the fetch tool takes any URL, and the file tools accept any absolute path on the machine. The only argument checks are that paths are absolute and commands are not empty; there is no workspace containment, host allowlist or block on internal addresses. Each agent has a tool list, but the default agent gets shell, write, remove, fetch, delegation and all MCP tools. A misused tool can therefore act on the whole machine and any reachable host.

C4 Code-execution isolation

Minimal 0.00 / 1.00

Every shell command the model writes runs directly on the host as the user, through the user's own shell, with the full environment. MCP stdio servers are also launched as ordinary host processes. The `--sandbox` flag only creates a separate git worktree and branch; it is not an isolation boundary. Anything the model runs, including repository scripts, can read and change everything the user can, and use every credential in the environment.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

Forge reads untrusted content from the web (fetch tool), repository files, command output and MCP tool results, and puts it into the model's context with no marking or special handling. In the same session it holds the user's credentials and can run shell commands, write files and make arbitrary web requests without asking. If injected text takes over the session, it can both send data out and make irreversible changes with no human involved.

C6 Memory, context & configuration integrity

Minimal 0.17 / 1.00

Forge loads several things from the project it is opened in without asking: `.env` files from the working directory and every parent directory (their FORGE_ settings and provider variables feed the configuration), AGENTS.md instructions, and custom agents, skills and commands under `.forge/`, where a project agent can replace the built-in default agent with its own tools and prompt. Only a project `.mcp.json` triggers a trust prompt, remembered per file content. The model can also write AGENTS.md, so injected instructions can persist into later sessions. Opening an untrusted repository can therefore change endpoints, settings and the agent's behaviour before the user does anything.

C7 Third-party extensions

Minimal 0.25 / 1.00

MCP servers are the main third-party extension. The user adds them by command line or URL in a user-scope file or a project `.mcp.json`; nothing is pinned or hash-checked, so a command like `npx some-server` runs whatever is current. A project `.mcp.json` triggers a trust prompt that is remembered per file content and asks again when the file changes, but the prompt shows only the file path, not the commands it will run, and the trust decision does not hold in every configuration. Launched servers are ordinary host processes that inherit the user's full environment.

C8 Secrets & sensitive-data protection

Minimal 0.15 / 1.00

Provider API keys are stored in a plaintext JSON file in the Forge config directory with owner-only permissions, and authorization headers are redacted in debug HTTP logs. Nothing else is masked: tool-call arguments are logged in full, shell commands inherit every secret in the environment, and the model can read the credentials file with its own tools. Release builds send usage telemetry to a third party by default, including the text of prompts, command-line arguments, the working directory and, on errors, the current conversation; the FORGE_TRACKER switch only removes the user-identifying extras.

C9 Audit & traceability

Moderate 0.50 / 1.00

Every tool call, including MCP tools, is logged with its full arguments before it runs, and the conversation, including tool calls and results, is saved to a local database in the Forge config directory after each model request. Sub-agent runs are saved as their own conversations. The record does not say who approved what, sub-agent conversations are not linked to the parent run, and both the database and the log files sit where the agent's own shell and file tools can change or delete them.

C10 Limits & kill switch

Minimal 0.40 / 1.00

Each turn stops after 100 model requests by default, every built-in and MCP tool call is cut off after 300 seconds, and a turn ends after three failures of the same tool. A loop detector only adds a reminder to the model. There is no token or cost budget, sub-agents start their own fresh request budget with no limit on delegation depth or parallel tasks, and a project's own agent files can set a higher per-turn cap. Ctrl+C stops the current operation and the shell child is killed, but background processes the commands started keep running.