C1 Identity & least privilege
Minimal 0.25 / 1.00
ZeroClaw runs every tool as the operating-system user who started it and holds the model-provider and channel keys in that process. It narrows that authority in useful ways: shell commands get a cleared environment with only a few functional variables, and file tools are confined to the agent workspace with sensitive home directories denied. MCP servers, however, are started with the full parent environment. A default model-routing tool can rewrite agent definitions, including which risk profile an agent is bound to and its tool allowlist, so the agent can widen its own permissions once an operator approves that call.
C2 Approval gates
Minimal 0.45 / 1.00
In the interactive CLI with the Locked Down preset, every tool call stops for a yes, no or always answer, and the runtime overwrites any approval flag the model tries to set itself. The prompt shows each argument cut to 80 characters, so a long command is not shown in full, and 'always' approves that tool for the rest of the session. Sub-agents and scheduled jobs run with no approval manager at all, and channel-driven turns let low-risk shell commands through without a human. There is no checkpoint or undo for consequential actions.
C3 Tool & action scoping
Minimal 0.40 / 1.00
File tools resolve paths, follow symlinks and check the result against the workspace and a deny list, and web fetch and HTTP tools block private addresses, pin DNS and recheck redirects. The shell tool is the weak point: it validates commands with an allowlist of executables plus argument filters and a name-based risk classifier, and the default allowlist includes interpreters and package tools. By default every tool is enabled, including shell, file write and generic HTTP to any public host, so a misused tool reaches far beyond its stated job.
C4 Code-execution isolation
Minimal 0.38 / 1.00
Shell, git and coding-CLI commands are wrapped by an automatically selected OS sandbox. On macOS that is a Seatbelt profile that denies network and limits writes to the workspace; on Linux it is Firejail if installed, with a private home and seccomp but no network isolation. The Landlock backend is not compiled into the default or release feature sets, and when no backend is available the shell silently runs on the host. MCP servers are launched as unsandboxed subprocesses.
C5 Untrusted input blast radius
Minimal 0.45 / 1.00
ZeroClaw reads web pages, search results, chat messages, email and MCP results, and none of it is tagged or treated differently from the user's instructions. What limits a hijacked turn is the approval gate: in the interactive CLI each consequential call needs a yes. Chat channels only accept allowlisted senders. But a single approved sub-agent spawn, a scheduled job or a channel-driven turn can then fetch any public URL, write workspace files or run low-risk shell commands with no human in the loop, which is enough to send private data out.
C6 Memory, context & configuration integrity
Minimal 0.35 / 1.00
Every turn's user message is auto-saved to memory, and recalled memories are injected inside a labelled memory block. The model's explicit memory-write tool needs approval in the scored preset. Personality files such as AGENTS.md and SOUL.md in the agent's workspace load silently into every system prompt, and skills in the workspace add tools; the agent can write both with its file tools after approval. The runtime config file is protected from file tools, and memory has default retention and purge windows.
C7 Third-party extensions
Minimal 0.30 / 1.00
Nothing third-party runs by default: WASM plugins are disabled and not in the release build, MCP has no servers configured, and community skills are opt-in with script files disallowed. When an operator adds them, MCP servers are launched from whatever command is configured, with no pinning or integrity check, as the same user with the full environment. Skills are installed with an unpinned shallow git clone plus a static content audit.
C8 Secrets & sensitive-data protection
Minimal 0.45 / 1.00
Secrets in the config file are encrypted by default with a locally stored key, credential-shaped strings are scrubbed from tool output before it reaches the model and from logs, tool input/output logging is masked by default and LLM request payloads are not logged. Telemetry export is off by default; a version-update check is on. Provider and channel keys are long-lived and sit in the agent process, and MCP servers receive the full environment.
C9 Audit & traceability
Minimal 0.47 / 1.00
Every tool call is recorded as a structured event with its scrubbed arguments, result, iteration and trace id, and approval decisions are recorded with the deciding channel. The trace file lives inside the agent workspace and is a rolling log with no tamper evidence. A hash-chained audit logger exists but is used for certificate events, not tool calls, and the signed tool receipts the README highlights are off by default.
C10 Limits & kill switch
Moderate 0.65 / 1.00
Runs are bounded by a 10-iteration tool loop, a $10 daily and $100 monthly cost ceiling enforced before each model call, a 60-second shell timeout and a rate limit of 20 actions per hour on shell and file tools. Shell commands run in their own process group, which is killed on cancel or timeout. Sub-agents share the parent's limits and cannot spawn their own sub-agents. Scheduled jobs keep running after a session stops, and the model can raise iteration and delegation limits for agent profiles through a default tool once approved.