# Defense-in-depth score: Archon

**Repo:** https://github.com/coleam00/Archon · **Commit:** `f326bb4d9e09ddb929b3740cae35d672d82e4b8b` · **Reviewed:** 2026-10-05
**What it is:** Workflow engine and harness that runs AI coding agents (Claude Code, Codex, Pi and others) through YAML-defined development workflows from a CLI, web UI or chat platforms.
**Category:** Coding
**Scored configuration:** The archon CLI (as driven by the bundled Claude Code skill) running the bundled sdlc workflow pack with the Claude provider on a repository project, default worktree isolation, no ~/.archon/config.yaml changes.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication yes

## Score: 1.7 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L0 | L0 | L0 | 0.00 | none | **0.00** | High |
| C2 | Approval gates | L0 | L0 | L0 | L1 | 0.05 | C2-POWERBYPASS | **0.05** | High |
| C3 | Tool & action scoping | L0 | L0 | L1 | L0 | 0.05 | none | **0.05** | High |
| C4 | Code-execution isolation | L1 | L2 | L0 | L1 | 0.28 | G1 | **0.28** (alt) | High |
| C5 | Untrusted input blast radius | L0 | L0 | L0 | L0 | 0.00 | C5-WORSTCASE | **0.00** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L0 | L0 | 0.00 | C6-REPOCONFIG | **0.00** | High |
| C7 | Third-party extensions | L2 | L1 | L0 | L0 | 0.23 | none | **0.23** | High |
| C8 | Secrets & sensitive-data protection | L2 | L2 | L1 | L0 | 0.35 | none | **0.35** | High |
| C9 | Audit & traceability | L2 | L2 | L2 | L1 | 0.45 | none | **0.45** | High |
| C10 | Limits & kill switch | L1 | L2 | L1 | L1 | 0.33 | none | **0.33** | High |


Archon runs Claude Code with permission prompts switched off (and Codex with approvals set to never), handing the agent the user's full environment and credentials and letting it act on GitHub issues, push branches and open pull requests unattended. The per-run git worktree keeps workflows from colliding but is not a security boundary, and the only container isolation is opt-in and limited to folder projects. Repositories can bring their own workflows, MCP servers, environment and assistant settings, which load without a trust prompt. Run it only on repositories and inputs you fully trust.

## Critical gaps
- Agent tools run with permission prompts bypassed, so shell commands, file writes and pushes need no human approval. (ASI09, ASI02; C2). Evidence: [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/providers/src/codex/provider.ts:986-987](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/codex/provider.ts#L986-L987)
- A paused workflow approval gate can be resolved by the chat model through its run-management tool. (ASI09; C2). Evidence: [packages/core/src/orchestrator/manage-run-tool.ts:74-78](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/orchestrator/manage-run-tool.ts#L74-L78); [packages/core/src/orchestrator/manage-run-tool.ts:296](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/orchestrator/manage-run-tool.ts#L296)
- The agent and all subprocesses inherit the user's full environment and credentials. (ASI03; C1). Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965)
- Model-driven commands run on the host as the user with no OS boundary in the default configuration, and a repository workflow can turn the worktree off. (ASI05; C4). Evidence: [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965); [packages/workflows/src/schemas/workflow.ts:66-70](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/workflow.ts#L66-L70)
- Content from GitHub issues and other sources reaches an agent that can leak credentials and push code with no approval step. (ASI01, LLM01; C5). Evidence: [.archon/workflows/sdlc/ship/archon-ship.yaml:15](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/ship/archon-ship.yaml#L15); [.archon/workflows/sdlc/.shared/pr.ts:237](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/.shared/pr.ts#L237); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982)
- Repository files load workflows, MCP servers, hooks, environment and assistant settings without a trust decision. (ASI06, ASI04; C6). Evidence: [packages/core/src/config/config-loader.ts:508](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L508); [packages/core/src/config/config-loader.ts:757](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L757); [packages/providers/src/claude/provider.ts:1678](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L1678)
- MCP servers run as the user and can be configured to receive any variable from the full environment. (ASI04; C7). Evidence: [packages/providers/src/mcp/config.ts:139](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/mcp/config.ts#L139); [packages/providers/src/claude/provider.ts:772](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L772)

## Criterion details

### C1 Identity & least privilege: 0.00 (high confidence)

Archon acts with whatever authority the person running it has. The Claude Code subprocess, bash and script nodes all receive the full environment of the Archon process, so every API key, GitHub token and cloud credential in it is available to the agent, and the agent runs Claude Code with permission prompts switched off. A per-user GitHub token policy exists for multi-user server installs, but it does nothing in the default single-user CLI setup. If the agent is steered wrong, it can do anything the user's own accounts allow.

- **S L0:** The agent inherits the operator's full ambient credentials; no scoped identity is issued for a run. Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965) (verified)
  - *To reach the next level:* No per-run or per-tool scoped identity; credentials are not narrowed for the agent.
- **C L0:** No authorization layer sits between tools and credentials: the Claude subprocess, bash nodes and script nodes all use the inherited environment directly. Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
  - *To reach the next level:* No authorization check on any tool path.
- **D L0:** The default solo install applies no GitHub token policy at all; the per-user scrub only runs when multi-user mode is on and a user started the run. Evidence: [packages/workflows/src/utils/github-token-policy.ts:53-54](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/utils/github-token-policy.ts#L53-L54) (verified)
  - *To reach the next level:* Least privilege requires enabling multi-user mode and per-user tokens.
- **B L0:** A hijacked run holds the user's GitHub token, model provider keys and any other credentials in the environment, plus full shell access as the user. Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/docs-web/src/content/docs/reference/security.md:31](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/docs-web/src/content/docs/reference/security.md#L31) (verified)
  - *To reach the next level:* Credentials reachable from a run are long-lived and span the user's accounts.
- **Cap:** none

### C2 Approval gates: 0.05 (high confidence)

Archon deliberately runs Claude Code in its permission-bypass mode and Codex with approvals set to never, so no individual command, file write, push or pull-request creation is shown to a human first; the project documents this as a design choice for unattended workflows. Workflows can include human approval gate nodes, but the bundled delivery workflow has none (the human gate is PR review on GitHub), and the chat assistant's run-management tool can itself approve or reject a paused gate. Changes happen in a git worktree by default, but pushes, PRs and anything done through the shell outside it are not reversible by Archon.

- **S L0:** There is no per-call approval; workflow approval gates can be resolved by the chat model through its run-management tool. Evidence: [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/providers/src/codex/provider.ts:986-987](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/codex/provider.ts#L986-L987); [packages/core/src/orchestrator/manage-run-tool.ts:74-78](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/orchestrator/manage-run-tool.ts#L74-L78); [packages/core/src/orchestrator/manage-run-tool.ts:296](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/orchestrator/manage-run-tool.ts#L296) (verified)
  - *To reach the next level:* No per-call human approval showing the exact command or diff.
- **C L0:** The shell and every other tool, including MCP tools, run without crossing any gate. Evidence: [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/docs-web/src/content/docs/reference/security.md:23](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/docs-web/src/content/docs/reference/security.md#L23) (verified)
  - *To reach the next level:* The most powerful tool path (shell) is ungated.
- **D L0:** Approval only exists where a workflow author adds a gate node; the bundled delivery workflow states it has no in-run approval gate. Evidence: [.archon/workflows/sdlc/deliver/archon-deliver.yaml:9](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/deliver/archon-deliver.yaml#L9); [packages/docs-web/src/content/docs/reference/security.md:14](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/docs-web/src/content/docs/reference/security.md#L14) (verified)
  - *To reach the next level:* Approval is opt-in per workflow.
- **B L1:** Runs default to a git worktree, which makes local code edits reversible, but pushes, PR creation, issue filing and host-wide shell actions are not. Evidence: [packages/cli/src/cli.ts:727](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/cli.ts#L727); [.archon/workflows/sdlc/.shared/pr.ts:237](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/.shared/pr.ts#L237); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
  - *To reach the next level:* No checkpoints or dry-runs for external actions; host shell actions outside the worktree are irreversible.
- **Cap:** C2-POWERBYPASS: The shell and all agent tools run with permission prompts bypassed in the default configuration.

### C3 Tool & action scoping: 0.05 (high confidence)

Agents get the full Claude Code (or Codex) tool set: arbitrary shell commands, file writes anywhere the user can write, and web access, with no argument validation by Archon. Workflow authors can restrict each node to a list of allowed or denied tools, which is a useful coarse control, but the bundled workflows don't use it and it never inspects arguments. A misused tool reaches the whole machine.

- **S L0:** Shell commands and file paths pass through to the provider unvalidated; per-node allowed_tools/denied_tools select tools but never check arguments. Evidence: [packages/providers/src/claude/provider.ts:730](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L730); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
  - *To reach the next level:* No argument-level allowlists (paths, hosts, commands) enforced in code.
- **C L0:** No tool validates its inputs on Archon's side. Evidence: [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/workflows/src/schemas/dag-node.ts:189-190](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L189-L190) (verified)
  - *To reach the next level:* Validation would have to exist on at least some tools.
- **D L1:** All tools, including shell, write and network, are enabled by default; a workflow node can narrow them with allowed_tools or denied_tools. Evidence: [packages/workflows/src/schemas/dag-node.ts:189-190](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L189-L190); [packages/providers/src/claude/provider.ts:730](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L730) (verified)
  - *To reach the next level:* Tool groups are not selectable at install level and the default set includes write and exec.
- **B L0:** A misused shell tool can act on the whole machine with the user's credentials. Evidence: [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217) (verified)
  - *To reach the next level:* Tools are not scoped to the workspace or bounded in quantity.
- **Cap:** none
- **Notes:** Deterministic bash and script nodes receive upstream values through environment variables or shell-safe substitution rather than raw string splicing, which reduces injection into the workflow's own steps; it does not constrain the agent's tools.

### C4 Code-execution isolation: 0.28 (high confidence)

For repository projects, which is how most people use Archon, every workflow run happens in a separate git worktree, but that is a working directory, not a boundary: Claude Code, bash nodes and script nodes all run as the user on the host with the full environment and permission prompts off. A workflow file can also pin the worktree off. An opt-in Docker container backend exists for folder projects only; it keeps the host environment out and caps memory and processes, but has open network egress, runs as root inside, and on a standard Docker daemon falls back to a mode the project's own security notes describe as escapable.

- **default configuration** (default; raw 0.20, cap G2 → 0.20)
  - **S L1:** The default isolation is a per-run git worktree, a separate working directory with no OS boundary. Evidence: [packages/cli/src/cli.ts:727](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/cli.ts#L727); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
    - *To reach the next level:* No OS-level separation (container, sandbox user, Seatbelt/Landlock) on the default path.
  - **C L1:** Claude, bash and script nodes use the worktree as their working directory, but the agent's shell and any spawned process can leave it freely. Evidence: [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
    - *To reach the next level:* Spawned processes and the agent's shell are not confined to the worktree.
  - **D L1:** Worktree isolation is on by default, but a workflow YAML in the repository can pin it off. Evidence: [packages/workflows/src/schemas/workflow.ts:66-70](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/workflow.ts#L66-L70); [packages/workflows/src/schemas/workflow.ts:208](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/workflow.ts#L208) (verified)
    - *To reach the next level:* A workspace file can disable the default isolation.
  - **B L0:** Code runs on the host as the user with the whole home directory and every credential in the environment reachable. Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965) (verified)
    - *To reach the next level:* Executed code reaches the home directory and credentials.
- **opt-in container backend (--container, folder projects only)** (alt; raw 0.28, cap G1 → 0.28) ← counted
  - **S L1:** Stock Docker container running as root; on a standard rootful daemon the overlay falls back to a mode that adds SYS_ADMIN and drops AppArmor, which the project documents as an isolation escape. Evidence: [packages/isolation/src/backends/container.ts:727](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/isolation/src/backends/container.ts#L727); [packages/isolation/docker/SECURITY.md:33](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/isolation/docker/SECURITY.md#L33) (verified)
    - *To reach the next level:* No hardened profile (non-root, dropped capabilities, no-new-privileges) on a standard daemon.
  - **C L2:** Within a container run, Claude, bash and script nodes all execute inside the container; repository projects cannot use it at all. Evidence: [packages/cli/src/commands/workflow.ts:324-327](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/commands/workflow.ts#L324-L327); [packages/providers/src/claude/provider.ts:246](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L246) (verified)
    - *To reach the next level:* Repository projects and chat sessions always run on the host.
  - **D L0:** Off by default and limited to folder projects. Evidence: [packages/cli/src/commands/workflow.ts:324-327](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/commands/workflow.ts#L324-L327) (verified)
    - *To reach the next level:* Not on by default.
  - **B L1:** The host environment is not passed in and memory/PID caps apply, but the default network is bridge (open egress) and managed credentials are delivered into the container. Evidence: [packages/cli/src/commands/workflow.ts:465-466](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/commands/workflow.ts#L465-L466); [packages/providers/src/claude/provider.ts:246](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L246) (verified)
    - *To reach the next level:* Network egress is open by default and credentials enter the container.
- **Cap:** G1: Opt-in mechanism: off in the scored default configuration.
- **Notes:** Workflow nodes can also pass Claude Code's own sandbox settings (sandbox:), opt-in per node and covering only Claude's shell tool; bundled workflows do not use it.

### C5 Untrusted input blast radius: 0.00 (high confidence)

The bundled workflows read GitHub issues, pull requests and repository content and feed them to an agent that can run any shell command, push branches and open pull requests, all without a human in the loop. Nothing in code marks or limits content from those sources; the only defence is prompt wording asking the model to treat issue text as claims. If injected text hijacks a run, it can both leak the credentials and files the agent can see and take irreversible actions such as pushing code.

- **S L0:** No structural limit on a hijacked run; the triage prompt asks the model to treat issue text as claims, which is a prompt, not a control. Evidence: [.archon/workflows/sdlc/triage/commands/triage.md:21](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/triage/commands/triage.md#L21); searched `rg -n -i -S 'untrusted|prompt.injection|spotlight|quarantin'` in `packages/core/src packages/workflows/src packages/providers/src` → 4 hits (three hits are prompt text inside generated bundled workflow defaults and one is a Codex protocol enum value; none is a code control acting on untrusted content) (verified)
  - *To reach the next level:* No code-enforced restriction once untrusted content has been read.
- **C L0:** Issue bodies, PR content, web pages, tool and MCP results all enter context with the same standing as the operator's instructions. Evidence: searched `rg -n -i -S 'untrusted|prompt.injection|spotlight|quarantin'` in `packages/core/src packages/workflows/src packages/providers/src` → 4 hits (three hits are prompt text inside generated bundled workflow defaults and one is a Codex protocol enum value; none is a code control acting on untrusted content) (verified)
  - *To reach the next level:* Untrusted sources are not distinguished.
- **D L0:** No control exists to be on by default. Evidence: searched `rg -n -i -S 'untrusted|prompt.injection|spotlight|quarantin'` in `packages/core/src packages/workflows/src packages/providers/src` → 4 hits (three hits are prompt text inside generated bundled workflow defaults and one is a Codex protocol enum value; none is a code control acting on untrusted content) (verified)
  - *To reach the next level:* No untrusted-input control ships.
- **B L0:** A hijacked run holds the user's credentials and can push code, open PRs and reach any URL with no approval step. Evidence: [.archon/workflows/sdlc/ship/archon-ship.yaml:15](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/ship/archon-ship.yaml#L15); [.archon/workflows/sdlc/.shared/pr.ts:237](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/.archon/workflows/sdlc/.shared/pr.ts#L237); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982); [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217) (verified)
  - *To reach the next level:* Exfiltration and irreversible actions both happen unattended.
- **Cap:** C5-WORSTCASE: Worst case (B L0): a hijacked agent can leak data and take irreversible actions unattended.

### C6 Memory, context & configuration integrity: 0.00 (high confidence)

Archon is designed so a repository carries its own automation: workflows, commands, scripts, an .archon/config.yaml (including environment variables and assistant settings), a repo-scope .archon/.env, and Claude Code project settings and CLAUDE.md are all loaded from the working checkout with no trust prompt. That means a cloned repository can add MCP servers, hooks and shell steps, and change how the agent is configured, simply by containing the right files; the project documents these sources as trusted. Conversation and run history persist in Archon's database and are scoped per project.

- **S L0:** Repository files can add workflows with shell steps, MCP servers and hooks, and set environment and assistant configuration, with no prompt. Evidence: [packages/core/src/config/config-loader.ts:508](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L508); [packages/core/src/config/config-loader.ts:757](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L757); [packages/workflows/src/schemas/dag-node.ts:193-194](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L193-L194); [packages/providers/src/claude/provider.ts:1678](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L1678); [packages/docs-web/src/content/docs/reference/security.md:131](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/docs-web/src/content/docs/reference/security.md#L131) (verified)
  - *To reach the next level:* No workspace-trust decision before repository configuration is applied.
- **C L0:** None of the auto-loaded repository sources is gated. Evidence: [packages/core/src/config/config-loader.ts:508](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L508); [packages/providers/src/claude/provider.ts:1678](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L1678) (verified)
  - *To reach the next level:* No auto-loaded config or memory path is controlled.
- **D L0:** Repository-committed configuration applies to everyone who runs Archon in that checkout; there are no per-user namespaces for project context. Evidence: [packages/core/src/config/config-loader.ts:508](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L508); [packages/docs-web/src/content/docs/reference/security.md:131](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/docs-web/src/content/docs/reference/security.md#L131) (verified)
  - *To reach the next level:* Project context is not isolated per user by default.
- **B L0:** Poisoned repository files persist across sessions and users and trigger tool use in every run. Evidence: [packages/core/src/config/config-loader.ts:508](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/config/config-loader.ts#L508); [packages/workflows/src/schemas/dag-node.ts:193-194](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L193-L194) (verified)
  - *To reach the next level:* Poisoned config persists and drives tools for every user of the repository.
- **Cap:** C6-REPOCONFIG: Files in the target repository (.archon/ config, env and workflows, Claude project settings) enable tools, MCP servers and hooks and change environment and assistant configuration without a user trust decision.

### C7 Third-party extensions: 0.23 (high confidence)

Archon's own plugins are installed explicitly from GitHub, pinned to a tag or commit, checked against the release's checksum file, and forge plugin processes get a scrubbed environment. MCP servers, Claude plugins and hooks are a different story: a workflow node can point at an MCP configuration in the repository, which is launched by whatever command it names, and that configuration can pull any environment variable into a server's environment or headers. Nothing verifies or confines these servers.

- **S L2:** Archon plugins resolve to a pinned tag or commit and forge binaries are compared with the release's checksums.txt; MCP servers are run unpinned. Evidence: [packages/cli/src/commands/plugin.ts:288-296](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/cli/src/commands/plugin.ts#L288-L296); [packages/providers/src/claude/provider.ts:772](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L772) (verified)
  - *To reach the next level:* Checksums come from the same release, not an independent signature or curated registry; MCP servers are not pinned.
- **C L1:** Only Archon plugins are verified; MCP servers, Claude plugins and hooks are not. Evidence: [packages/providers/src/claude/provider.ts:772](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L772); [packages/workflows/src/schemas/dag-node.ts:193-194](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L193-L194) (verified)
  - *To reach the next level:* MCP servers, Claude plugins and hooks have no verification.
- **D L0:** A workflow file in the repository can add MCP servers and hooks with no install step or prompt. Evidence: [packages/workflows/src/schemas/dag-node.ts:193-194](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L193-L194); [packages/providers/src/claude/provider.ts:772](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L772) (verified)
  - *To reach the next level:* Workspace files can add extensions silently.
- **B L0:** MCP servers run as the user and their configuration can expand any variable from the full Archon environment into their env and headers. Evidence: [packages/providers/src/mcp/config.ts:139](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/mcp/config.ts#L139); [packages/providers/src/mcp/config.ts:94](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/mcp/config.ts#L94); [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217) (verified)
  - *To reach the next level:* MCP servers are not given a scrubbed environment or their own scoped credentials.
- **Cap:** none
- **Notes:** Forge plugin processes do receive a scrubbed environment (packages/forge/src/plugin-process.ts:45-48).

### C8 Secrets & sensitive-data protection: 0.35 (high confidence)

Archon has real secret hygiene in places: per-user provider and GitHub credentials are encrypted at rest with AES-256-GCM, never returned by the API, and bash/script output is redacted against secret-named environment values before it is logged or retained. But in the default setup secrets live in environment files and are passed whole to the agent and every subprocess, so the model can read them, and node output passed on to the next model step is not redacted. Anonymous, content-free telemetry is on by default with documented opt-outs.

- **S L2:** Per-user credentials are encrypted at rest and subprocess output is redacted against secret-named env values; solo secrets are plaintext env files. Evidence: [packages/core/src/utils/token-crypto.ts:7](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/utils/token-crypto.ts#L7); [packages/paths/src/credential-redaction.ts:10](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/paths/src/credential-redaction.ts#L10); [packages/paths/src/credential-redaction.ts:38](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/paths/src/credential-redaction.ts#L38) (verified)
  - *To reach the next level:* No keychain/secret manager by default and no redaction before model-bound messages.
- **C L2:** Redaction covers retained exec logs and error output; downstream node input and the agent's own tool output are not redacted, and subprocess environments carry every secret. Evidence: [packages/workflows/src/dag-executor.ts:2998](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2998); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965) (verified)
  - *To reach the next level:* Model-bound messages and subprocess environments are not protected.
- **D L1:** Content-free telemetry is on by default with opt-out variables. Evidence: [packages/paths/src/telemetry.ts:32-35](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/paths/src/telemetry.ts#L32-L35) (verified)
  - *To reach the next level:* Telemetry is opt-out rather than opt-in.
- **B L0:** Long-lived provider keys and GitHub tokens are reachable by the model and by every subprocess. Evidence: [packages/providers/src/claude/provider.ts:217](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L217); [packages/workflows/src/dag-executor.ts:2965](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2965) (verified)
  - *To reach the next level:* Credentials reachable by the model are long-lived and broad.
- **Cap:** none

### C9 Audit & traceability: 0.45 (high confidence)

Each workflow run writes a structured JSONL log and database events covering node starts and ends, provider tool calls, bash and script output, and gate decisions, stored under Archon's home directory rather than in the worktree. The record has no actor attribution for approvals, the agent runs as the same user and could edit it, and a logging failure only produces a single warning while the run carries on.

- **S L2:** Structured per-run JSONL and database events with timestamps; gate decisions record no actor. Evidence: [packages/workflows/src/logger.ts:155](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L155); [packages/workflows/src/logger.ts:282](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L282); [packages/core/src/db/workflow-events.ts:110](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/db/workflow-events.ts#L110) (verified)
  - *To reach the next level:* No actor attribution (approver, requesting principal) on records.
- **C L2:** Workflow node execution, provider tool calls and gate decisions are recorded; coverage of chat-mode tool activity and configuration changes in the same record was not shown. Evidence: [packages/workflows/src/logger.ts:155](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L155); [packages/workflows/src/logger.ts:282](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L282) (verified)
  - *To reach the next level:* Chat sessions and configuration changes are not shown to land in the same audit record.
- **D L2:** On by default and stored under the Archon home, outside the worktree, but the agent runs as the same user and can alter it. Evidence: [packages/workflows/src/logger.ts:130](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L130); [packages/providers/src/claude/provider.ts:981-982](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L981-L982) (verified)
  - *To reach the next level:* The record is writable by the agent's own process.
- **B L1:** Each event is appended as it happens, but a write failure is warned about once and the run continues. Evidence: [packages/workflows/src/logger.ts:162-163](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/logger.ts#L162-L163) (verified)
  - *To reach the next level:* Logging failures do not surface per action or stop execution.
- **Cap:** none

### C10 Limits & kill switch: 0.33 (high confidence)

Workflow structure bounds the overall run: loops must declare a maximum iteration count, sub-workflow nesting is capped, and bash and script steps time out after two minutes by default. Inside an AI step, though, nothing caps turns, time or spend by default: the 30-minute idle timer resets on any output and is described as a deadlock detector, and a dollar budget exists only if a workflow sets it. Cancelling a run aborts the in-flight provider call.

- **S L1:** Workflow loops carry mandatory iteration caps and exec steps a default timeout, but the agent's own loop inside an AI step has no turn cap, no time limit beyond an idle watchdog and only an optional per-node budget. Evidence: [packages/workflows/src/schemas/loop.ts:81](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/loop.ts#L81); [packages/workflows/src/dag-executor.ts:2819](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2819); [packages/workflows/src/utils/idle-timeout.ts:17-22](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/utils/idle-timeout.ts#L17-L22); [packages/workflows/src/schemas/dag-node.ts:223](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L223); [packages/providers/src/claude/provider.ts:1651](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/providers/src/claude/provider.ts#L1651) (verified)
  - *To reach the next level:* No iteration cap or per-execution timeout on the agent loop inside AI steps.
- **C L2:** Limits apply to the workflow graph and to exec steps; sub-workflow depth is capped, but AI steps and their sub-agents share no common budget. Evidence: [packages/core/src/db/workflows.ts:802](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/core/src/db/workflows.ts#L802); [packages/workflows/src/dag-executor.ts:2819](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/dag-executor.ts#L2819) (verified)
  - *To reach the next level:* Sub-agents and child runs do not count against a shared budget.
- **D L1:** Default ceilings on AI steps are effectively unbounded and the limits that exist are set by the workflow file. Evidence: [packages/workflows/src/utils/idle-timeout.ts:17-22](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/utils/idle-timeout.ts#L17-L22); [packages/workflows/src/schemas/dag-node.ts:223](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/schemas/dag-node.ts#L223) (verified)
  - *To reach the next level:* No sensible default spend or turn ceiling for AI steps.
- **B L1:** A runaway AI step can keep working and spending as long as it produces output. Evidence: [packages/workflows/src/utils/idle-timeout.ts:17-22](https://github.com/coleam00/Archon/blob/f326bb4d9e09ddb929b3740cae35d672d82e4b8b/packages/workflows/src/utils/idle-timeout.ts#L17-L22) (verified)
  - *To reach the next level:* Per-run time and cost ceilings are not tight.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: GitHub issues and PRs read by the bundled sdlc pack (.archon/workflows/sdlc/ship/archon-ship.yaml:15), web fetches and repository content · [B] sensitive data/systems: Full process environment with provider keys and GitHub token (packages/providers/src/claude/provider.ts:217) · [C] state change / egress: Unapproved shell, git push and gh pr create (.archon/workflows/sdlc/.shared/pr.ts:237; packages/providers/src/claude/provider.ts:981) · Same default session? Yes

## Highest-impact improvements
1. Stop passing the whole process environment to the agent and subprocesses on host runs; deliver only the managed credential bag, as container runs already do. (C8 B L0→L2, +0.100 before caps; Playbook 4)
2. Require an explicit, user-scope trust decision before applying a repository's .archon/ config, env, workflows and Claude project settings. (C6 S L0→L3, +0.225 before caps; Playbook 2)
3. Make approval gates resolvable only by an authenticated human (CLI or UI), not by the chat model's manage_run tool. (C2 D L0→L2, +0.100 before caps; Playbook 5)
4. Offer a default-on OS sandbox for repository projects (Claude Code sandbox settings or the container backend) with egress restricted. (C4 S L1→L3, +0.150 before caps; Playbook 3)
5. Set default per-node turn and dollar budgets for AI steps and a run-level wall-clock limit. (C10 D L1→L2, +0.050 before caps; Playbook 3 step 3)

## Re-audit log
- C10 S: L2 → L1. The iteration caps and the 120 s default timeout apply to workflow loops and bash/script steps; the agent loop inside an AI step has neither a turn cap nor a per-execution timeout (only a 30-minute idle watchdog that resets on any output), so the evidence sits between L1 and L2 and takes the lower level.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- The scored configuration is the CLI with the Claude provider; the web server (archon serve), Docker compose deployment and chat adapters were reviewed only for their documented defaults and are not separately scored. In those modes the documented defaults include no built-in authentication for solo installs and open access for chat adapters without an allowlist.
- Codex, Pi, OpenCode and Copilot providers were reviewed only for their approval and sandbox settings.
- Behaviour of the Claude Agent SDK and Claude Code (how MCP servers inherit environment, how project settings load) is taken from their documented behaviour, not from their source.
- No reviewer-steering text was found in the repository's markdown files.
