# Defense-in-Depth Score: OpenHuman

**Repo:** https://github.com/tinyhumansai/openhuman · **Commit:** `cbde5069dec828c117131ee75f9d2bbeb5bda02b` · **Reviewed:** 2026-10-05
**What it is:** Rust open-source agent harness
**Category:** AI Assistants
**Scored configuration:** Desktop app (Tauri shell) with the default orchestrator agent, signed in to the managed TinyHumans backend, fresh config with all shipped defaults ([autonomy] enabled = false).
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions opt-in · sub agents yes · external communication opt-in

## Score: 3.5 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L1 | L1 | L1 | L1 | 0.25 | — | **0.25** | High |
| C2 | Approval gates | L2 | L2 | L0 | L1 | 0.35 | G1 | **0.35** (alt) | High |
| C3 | Tool & action scoping | L2 | L2 | L1 | L2 | 0.45 | G1 | **0.45** (alt) | High |
| C4 | Code-execution isolation | L2 | L1 | L2 | L1 | 0.38 | — | **0.38** | High |
| C5 | Untrusted input blast radius | L1 | L2 | L2 | L0 | 0.33 | C5-WORSTCASE | **0.25** | High |
| C6 | Memory, context & configuration integrity | L1 | L1 | L2 | L1 | 0.30 | — | **0.30** | High |
| C7 | Third-party extensions | L1 | L1 | L2 | L1 | 0.30 | — | **0.30** | Medium |
| C8 | Secrets & sensitive-data protection | L3 | L2 | L0 | L1 | 0.42 | — | **0.42** | High |
| C9 | Audit & traceability | L2 | L2 | L1 | L1 | 0.40 | — | **0.40** | High |
| C10 | Limits & kill switch | L2 | L2 | L1 | L1 | 0.40 | — | **0.40** | High |


OpenHuman contains a lot of security machinery, including an approval gate, command classification, path containment, an OS jail for shell commands, a keychain-backed secret store and credential scrubbing. The policy that turns most of it on ships disabled. As shipped, the agent runs shell commands, writes files outside credential folders and reaches any public website without asking, so a prompt injection in a web page or email can leak data and change files unattended. Prompts and tool output are also shared with the vendor's tracing backend by default. Turn on the autonomy policy and switch off usage-data sharing before giving it real accounts.

## Critical gaps
- The shell tool, the most powerful action path, runs without any approval in the default configuration because the autonomy policy that drives its approval decision ships disabled. (ASI02, ASI09; C2) — [crates/openhuman-core/src/config/schema/autonomy.rs:195](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L195); [crates/openhuman-core/src/security/policy/command_checks.rs:164-167](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L164-L167); [crates/openhuman-core/src/tools/impl/system/shell.rs:252-265](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L252-L265)
- A hijacked session can both send data to arbitrary public hosts and modify files without human involvement in the default configuration. (ASI01, LLM01; C5) — [crates/openhuman-core/src/security/policy/command_checks.rs:164-167](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L164-L167); [crates/openhuman-core/src/config/schema/tools/http.rs:32-34](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/tools/http.rs#L32-L34); [crates/openhuman-core/src/sandbox/ops.rs:94-97](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L94-L97)

## Criterion details

### C1 Identity & least privilege — 0.25 (high)

OpenHuman runs as the logged-in user with that user's file access, and in the shipped configuration nothing narrows that authority for file tools beyond a fixed block on credential stores such as ~/.ssh and ~/.aws. The shell tool strips the environment down to a short allowlist before running commands, but scheduled shell jobs and MCP server processes are started without that scrubbing. Connected apps reached through Composio are limited by a per-toolkit scope preference that allows reads and writes but not admin actions by default. A hijacked agent can therefore read most of the home directory, write files, reach the network and use connected accounts, with write actions on connected apps still needing a click in the chat.

- **S L1:** The agent uses the OS user's ambient authority; the main narrowing is environment scrubbing for shell children and a code-level Composio scope filter that blocks admin actions. — [crates/openhuman-core/src/tools/impl/system/shell.rs:17-40](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L17-L40); [crates/openhuman-core/src/tools/impl/system/shell.rs:391-397](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L391-L397); [crates/openhuman-core/src/integrations/composio/contract/scopes.rs:106-113](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/contract/scopes.rs#L106-L113) (verified)
  - *To reach the next level:* No per-tool or per-capability credentials: read and write tools share the user's identity and the same connected-app grants.
- **C L1:** The shell path clears the environment, but scheduled shell jobs are spawned without clearing it and run with the core's full environment. — [crates/openhuman-core/src/tools/impl/system/shell.rs:391-397](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L391-L397); [crates/openhuman-core/src/cron/scheduler/shell_job.rs:139-147](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/cron/scheduler/shell_job.rs#L139-L147) (verified)
  - *To reach the next level:* Every subprocess path (cron jobs, MCP stdio servers, language runtimes) would need the same scrubbed environment and authorization layer.
- **D L1:** Composio scopes default to read plus write, and an empty per-channel permission map (the fresh-install state) resolves to the unrestricted Dangerous level. — [crates/openhuman-core/src/integrations/composio/contract/scopes.rs:106-113](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/contract/scopes.rs#L106-L113); [crates/openhuman-core/src/tools/agent_policy/engine.rs:135-150](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/agent_policy/engine.rs#L135-L150) (verified)
  - *To reach the next level:* A near-minimal default (read-only connected apps, explicit channel ceilings) with writes enabled only by an explicit operator elevation.
- **B L1:** A hijacked session can write across the user's files outside credential stores and reach the network; Composio write actions remain behind a per-call approval in the web chat, which is the surviving layer. — [crates/openhuman-core/src/security/policy/path_checks.rs:472-477](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L472-L477); [crates/openhuman-core/src/security/policy/path_checks.rs:63-74](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L63-L74); [crates/openhuman-core/src/integrations/composio/tools/execute.rs:91-98](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/tools/execute.rs#L91-L98) (verified)
  - *To reach the next level:* Blast radius would need to be limited to one project with mostly read access and non-destructive writes.
- **Cap:** none

### C2 Approval gates — 0.35 (high)

OpenHuman ships a capable approval gate, but in the default configuration it only fires for a subset of tools that are hard-wired as consequential: Composio write actions, cron job changes, saving workflows and skill installs. The shell, file-write and HTTP tools ask the autonomy policy whether to prompt, and that policy is off by default, so they run without any approval. With the policy turned on (Supervised mode) every acting shell command, file write and network call is classified and parked for a human, with compound commands split and hidden execution blocked. Even then the approval card shows a code-built summary with recipients, message bodies and code fields masked, so the approver does not see the exact call.

- **default configuration** (default; raw 0.20, cap C2-POWERBYPASS → 0.20)
  - **S L2:** Per-call approval exists, but the card carries a generated summary and masked arguments that hide recipients, bodies and code. — [crates/openhuman-core/src/agent/tinyagents/middleware/approval.rs:136-139](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/middleware/approval.rs#L136-L139); [crates/openhuman-core/src/security/approval/redact.rs:243-248](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/approval/redact.rs#L243-L248); [crates/openhuman-core/src/security/approval/redact.rs:36-38](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/approval/redact.rs#L36-L38) (verified)
    - *To reach the next level:* The approver would need to see the exact command, arguments, diff or recipient being approved.
  - **C L0:** Shell, file-write and network tools only request approval when the autonomy policy prompts, and the disabled policy answers Allow for every class. — [crates/openhuman-core/src/tools/impl/system/shell.rs:252-265](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L252-L265); [crates/openhuman-core/src/security/policy/command_checks.rs:164-167](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L164-L167) (verified)
    - *To reach the next level:* The shell and file tools would need to cross the gate in the shipped configuration.
  - **D L0:** The policy that drives approval for the acting tools defaults to disabled. — [crates/openhuman-core/src/config/schema/autonomy.rs:195](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L195); [crates/openhuman-core/src/config/schema/autonomy.rs:11-31](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L11-L31) (verified)
    - *To reach the next level:* Approval for the acting tools would need to be on by default.
  - **B L1:** There is no checkpoint or undo for shell and file changes, and connected-app sends are irreversible once approved. — [crates/openhuman-core/src/integrations/composio/tools/execute.rs:91-98](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/tools/execute.rs#L91-L98); [crates/openhuman-core/src/tools/impl/system/shell.rs:252-265](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L252-L265) (verified)
    - *To reach the next level:* Reversible defaults (checkpoints or trash) for file and code state and previews for external actions.
- **opt-in autonomy policy ([autonomy] enabled = true, Supervised)** (alt; raw 0.35, cap G1 → 0.35) ← counted
  - **S L2:** Supervised mode prompts on every acting class, but the approval card still shows a masked summary rather than the exact call. — [crates/openhuman-core/src/security/policy/command_checks.rs:164-167](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L164-L167); [crates/openhuman-core/src/agent/tinyagents/middleware/approval.rs:136-139](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/middleware/approval.rs#L136-L139); [crates/openhuman-core/src/security/approval/redact.rs:243-248](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/approval/redact.rs#L243-L248) (verified)
    - *To reach the next level:* Show the exact call to the approver and bind the approval to it.
  - **C L2:** Shell commands are split on separators with the highest class winning and hidden execution blocked; MCP tool gating depends on the effect the server's tool reports. — [crates/openhuman-core/src/security/policy/command_checks.rs:129-155](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L129-L155); [crates/openhuman-core/src/security/policy/command_checks.rs:214-222](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L214-L222); [crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs:189-191](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs#L189-L191) (verified)
    - *To reach the next level:* Extension tools would need to be gated independently of what the server declares about itself.
  - **D L0:** The whole policy, and with it this approval path, is off unless the operator enables it. — [crates/openhuman-core/src/config/schema/autonomy.rs:195](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L195) (verified)
    - *To reach the next level:* Enable the policy by default.
  - **B L1:** Same irreversible outcomes as the default once a call is approved. — [crates/openhuman-core/src/integrations/composio/tools/execute.rs:91-98](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/tools/execute.rs#L91-L98) (verified)
    - *To reach the next level:* Checkpoints for file and code state and previews for external actions.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C3 Tool & action scoping — 0.45 (high)

Tools are broad by default: a raw shell, file read and write anywhere outside a short list of credential and system directories, and HTTP fetching allowed to any public host. The opt-in autonomy policy adds real containment, resolving paths and checking them against the working folder, a command allowlist and per-tier blocking, but it is disabled in the shipped configuration. Outbound fetches are checked against an allowed-domains list whose default is every public site, with private addresses blocked by the network tools.

- **default configuration** (default; raw 0.28 → 0.28)
  - **S L1:** With the policy disabled, path validation reduces to a fixed denylist of credential and system locations, and the shell takes an arbitrary command string. — [crates/openhuman-core/src/security/policy/path_checks.rs:63-74](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L63-L74); [crates/openhuman-core/src/security/policy/path_checks.rs:472-477](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L472-L477) (verified)
    - *To reach the next level:* Allowlist validation in code: resolved-path containment and host allowlists applied in the default configuration.
  - **C L2:** File and network tools all route through the shared policy adapter, so the same (weak) checks apply across built-in tools. — [crates/openhuman-core/src/tools/impl/filesystem/gate.rs:1-5](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/filesystem/gate.rs#L1-L5); [crates/openhuman-core/src/tools/impl/network/gate.rs:36-55](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/network/gate.rs#L36-L55) (verified)
    - *To reach the next level:* Extension tools would need to pass the same validation layer.
  - **D L0:** Shell, write and network tools are all enabled by default, and the fetch allowlist defaults to every public site. — [crates/openhuman-core/src/config/schema/tools/http.rs:32-34](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/tools/http.rs#L32-L34); [crates/openhuman-core/src/config/schema/autonomy.rs:195](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L195) (verified)
    - *To reach the next level:* Dangerous tools would need to be individually disableable defaults or off until enabled.
  - **B L1:** A misused tool reaches most of the user's home directory and any public host; shell writes are confined to the working folder by the jail where one is available. — [crates/openhuman-core/src/sandbox/ops.rs:61-78](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L61-L78); [crates/openhuman-core/src/config/schema/tools/http.rs:32-34](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/tools/http.rs#L32-L34) (verified)
    - *To reach the next level:* Scope tools to the project with quantity bounds.
- **opt-in autonomy policy with workspace containment** (alt; raw 0.45, cap G1 → 0.45) ← counted
  - **S L2:** Resolved paths are checked for containment in the workspace or a trusted root; commands use a base-name allowlist that still admits general tools such as git, make and npm. — [crates/openhuman-core/src/security/policy/path_checks.rs:552-563](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L552-L563); [crates/openhuman-core/src/config/schema/autonomy.rs:103-115](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L103-L115) (verified)
    - *To reach the next level:* Narrow, argument-aware allowlists and host allowlists in place of the general shell.
  - **C L2:** All built-in file, shell and network tools consult the policy. — [crates/openhuman-core/src/tools/impl/network/gate.rs:36-55](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/network/gate.rs#L36-L55); [crates/openhuman-core/src/security/policy/command_checks.rs:129-155](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L129-L155) (verified)
    - *To reach the next level:* Extension tools through a shared validation layer.
  - **D L1:** Even with the policy on, every tool family stays registered; risky ones are prompted or blocked per tier. — [crates/openhuman-core/src/config/schema/autonomy.rs:195](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/autonomy.rs#L195) (verified)
    - *To reach the next level:* A read-only default tool set.
  - **B L2:** Writes are contained to the workspace and trusted roots. — [crates/openhuman-core/src/security/policy/path_checks.rs:552-563](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L552-L563) (verified)
    - *To reach the next level:* Quantity bounds on consequential operations.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C4 Code-execution isolation — 0.38 (high)

The default user-facing agent runs shell, Python, Node and npm commands inside an OS jail (Landlock on Linux, Seatbelt on macOS) that confines writes to the working folder and strips the environment. Network access stays open for local sessions, the macOS profile allows reads everywhere, and on hosts with no usable jail (including Windows) commands silently run unconfined. Several paths sit outside the jail: scheduled shell jobs, MCP servers started as subprocesses, in-process file writes, and agents whose definition does not ask for a sandbox. An environment variable turns the jail off for the whole process.

- **S L2:** Basic OS-level confinement: writes limited to the working folder plus grants, but network allowed for local sessions. — [crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml:9-10](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml#L9-L10); [crates/openhuman-core/src/sandbox/ops.rs:94-97](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L94-L97); [crates/openhuman-core/src/tools/impl/system/shell.rs:368-376](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L368-L376) (verified)
  - *To reach the next level:* A hardened sandbox with network denied by default and reads limited on every platform.
- **C L1:** The scripting tools route through the jail when the agent is in sandboxed mode, but cron shell jobs spawn directly on the host and agents built from the custom registry default to no sandbox. — [crates/openhuman-core/src/tools/impl/system/shell.rs:368-376](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L368-L376); [crates/openhuman-core/src/cron/scheduler/shell_job.rs:139-147](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/cron/scheduler/shell_job.rs#L139-L147); [crates/openhuman-core/src/agent/registry/defaults.rs:102](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/registry/defaults.rs#L102) (verified)
  - *To reach the next level:* Every model-reachable execution path would need to run through the sandbox.
- **D L2:** On by default for the orchestrator, but OPENHUMAN_SANDBOX disables it and a host without a jail silently falls back to the no-op backend. — [crates/openhuman-core/src/sandbox/ops.rs:31](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L31); [crates/openhuman-core/src/sandbox/ops.rs:61-78](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L61-L78); [crates/openhuman-core/src/sandbox/ops.rs:398-404](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L398-L404) (verified)
  - *To reach the next level:* Fail closed when no jail is available and require an explicit, visible operator flag to disable.
- **B L1:** Inside the jail a command has open network egress and, on macOS, read access across the home directory; secrets are not in its environment. — [crates/openhuman-core/src/sandbox/ops.rs:94-97](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L94-L97); [crates/openhuman-core/src/sandbox/ops.rs:20-22](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/sandbox/ops.rs#L20-L22) (verified)
  - *To reach the next level:* Workspace-only access with egress off or allowlisted.
- **Cap:** none
- **Notes:** The shell tool builds its sandbox policy from RuntimeConfig::default(), so a configured Docker runtime is not used by the local shell path.

### C5 Untrusted input blast radius — 0.25 (high)

OpenHuman reads plenty of content its user did not write: web pages and search results, email and other connected-app data, synced memory sources and MCP tool results. Text entering the conversation passes a regex and heuristic prompt-injection screen, and remote MCP tool descriptions are screened before use. Nothing ties the agent's capabilities to having read untrusted content: in the shipped configuration a hijacked session can send data to any public host through the shell or HTTP tools and modify files without a human in the loop.

- **S L1:** Detection only: a deterministic regex and heuristic screen on content entering context. — [crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs:634-651](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs#L634-L651); [crates/openhuman-core/src/mcp/registry/mod.rs:472-480](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/mcp/registry/mod.rs#L472-L480) (verified)
  - *To reach the next level:* Disable or gate egress and state-changing tools once untrusted content is in the session.
- **C L2:** The screen covers user, tool output, web, channel, sub-agent and stored-memory origins, and MCP tool descriptions. — [crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs:634-651](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs#L634-L651); [crates/openhuman-core/src/mcp/registry/mod.rs:472-480](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/mcp/registry/mod.rs#L472-L480) (verified)
  - *To reach the next level:* Every source handled by a capability limit rather than detection.
- **D L2:** The screen is always on; nothing the agent reads can switch it off. — [crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs:634-651](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs#L634-L651) (verified)
  - *To reach the next level:* A structural limit that is on by default and cannot be configured away by content.
- **B L0:** With the autonomy policy disabled, egress through the shell and HTTP tools and file modification both proceed unattended after untrusted content is read. — [crates/openhuman-core/src/security/policy/command_checks.rs:164-167](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/command_checks.rs#L164-L167); [crates/openhuman-core/src/config/schema/tools/http.rs:32-34](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/tools/http.rs#L32-L34); [crates/openhuman-core/src/tools/impl/system/shell.rs:252-265](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L252-L265) (verified)
  - *To reach the next level:* Both exfiltration and irreversible actions would need human approval.
- **Cap:** C5-WORSTCASE — Worst case (B L0): a hijacked agent can leak data and take irreversible actions unattended.

### C6 Memory, context & configuration integrity — 0.30 (high)

When the user is signed in, memory is on by default: each turn is logged to the TinyHumans memory engine and relevant items are recalled into the next turn. Writes are scrubbed of secrets and personal data but not checked for instructions, so injected text can persist and resurface in later sessions. An AGENTS.md file in the working folder is loaded silently into the system prompt. Persona files such as SOUL.md are only protected from agent writes when the autonomy policy is enabled.

- **S L1:** Memory writes are scrubbed for secrets only, and project AGENTS.md is loaded without a trust decision. — [crates/openhuman-core/src/memory/guard.rs:69-71](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/memory/guard.rs#L69-L71); [crates/openhuman-core/src/agent/prompts/agents_md.rs:4-10](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/prompts/agents_md.rs#L4-L10) (verified)
  - *To reach the next level:* Gate memory writes (validation or approval) and require a trust decision for project instruction files.
- **C L1:** The scrubber wraps every memory engine write; instruction files and workspace persona files are not controlled in the default configuration. — [crates/openhuman-core/src/memory/guard.rs:69-71](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/memory/guard.rs#L69-L71); [crates/openhuman-core/src/security/policy/types.rs:220-232](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/types.rs#L220-L232); [crates/openhuman-core/src/security/policy/path_checks.rs:63-74](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L63-L74) (verified)
  - *To reach the next level:* Controls over every store, including auto-loaded instruction files.
- **D L2:** Memory is resolved per acting identity and agent rather than shared globally. — [crates/openhuman-core/src/memory/scope.rs:53](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/memory/scope.rs#L53); [crates/openhuman-core/src/config/schema/memory.rs:67](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/memory.rs#L67) (verified)
  - *To reach the next level:* Prevent the model from writing outside its namespace and add retention limits by default.
- **B L1:** Poisoned memory persists across the user's sessions and is recalled before turns that can use tools. — [crates/openhuman-core/src/memory/lifecycle/hooks.rs:147](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/memory/lifecycle/hooks.rs#L147); [crates/openhuman-core/src/config/schema/memory.rs:67](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/memory.rs#L67) (verified)
  - *To reach the next level:* Memory that is session-scoped or easy to inspect and purge before it influences tool use.
- **Cap:** none

### C7 Third-party extensions — 0.30 (medium)

Third-party code mainly arrives as MCP servers the user declares in an mcp.json document; there is no install-from-catalog tool for MCP, and remote tool descriptions are screened before reaching the agent. Declared servers are launched as given, with no version pinning or hash check. Skills from the public catalog are Markdown instructions and their install tools require approval. MCP server processes run as the same user and, from the vendored client, start with the core's environment rather than a scrubbed one.

- **S L1:** Servers are user-chosen and launched from the declared command without pinning or integrity checks. — [crates/openhuman-core/src/mcp/registry/mod.rs:472-480](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/mcp/registry/mod.rs#L472-L480); [crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs:189-191](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs#L189-L191) (verified)
  - *To reach the next level:* Pin versions and verify hashes or signatures.
- **C L1:** Only tool-description screening applies, and only to MCP servers. — [crates/openhuman-core/src/mcp/registry/mod.rs:472-480](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/mcp/registry/mod.rs#L472-L480) (verified)
  - *To reach the next level:* Verification across all extension types.
- **D L2:** No MCP server is enabled by default and servers are added by the user in a user-scope document. — [crates/openhuman-core/src/mcp/registry/mod.rs:472-480](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/mcp/registry/mod.rs#L472-L480) (verified)
  - *To reach the next level:* Show the exact package, command and permissions when a server is added.
- **B L1:** MCP servers run as separate processes under the same user; the vendored stdio client adds variables to the inherited environment rather than clearing it. — [crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs:189-191](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/network/mcp_server_tools.rs#L189-L191) (inferred)
  - *To reach the next level:* A scrubbed environment carrying only the server's own configuration.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.42 (high)

Secrets are handled well at rest: the OS keychain backs stored credentials, config secrets are encrypted, tool results are scrubbed of credential-looking strings before the model sees them, and the event journal masks process secrets. The weak point is telemetry: usage-data sharing is on by default and, with content capture also on by default, prompts, replies and truncated tool input and output are sent to the vendor's Langfuse proxy. Scheduled jobs and MCP servers also inherit the full process environment.

- **S L3:** OS keychain storage, encrypted config secrets, credential scrubbing on tool results and secret masking in the journal. — [crates/openhuman-core/src/security/keyring/backend.rs:38-45](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/keyring/backend.rs#L38-L45); [crates/openhuman-core/src/agent/tinyagents/middleware/credential_scrub.rs:63-66](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/middleware/credential_scrub.rs#L63-L66); [crates/openhuman-core/src/agent/tinyagents/journal.rs:193-198](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/journal.rs#L193-L198) (verified)
  - *To reach the next level:* Keep secrets out of model context by design and scan outputs for secret patterns everywhere.
- **C L2:** Logs, journals and model-bound tool results are covered; telemetry spans carry content and some subprocess environments are not scrubbed. — [crates/openhuman-core/src/agent/tinyagents/middleware/credential_scrub.rs:63-66](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/middleware/credential_scrub.rs#L63-L66); [crates/openhuman-core/src/agent/progress_tracing/export.rs:95-99](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/progress_tracing/export.rs#L95-L99); [crates/openhuman-core/src/cron/scheduler/shell_job.rs:139-147](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/cron/scheduler/shell_job.rs#L139-L147) (verified)
  - *To reach the next level:* Cover telemetry and every subprocess environment.
- **D L0:** Usage-data sharing and content capture both default on, sending prompts and tool I/O off the device. — [crates/openhuman-core/src/config/schema/observability.rs:42-44](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/observability.rs#L42-L44); [crates/openhuman-core/src/config/schema/observability.rs:20-28](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/observability.rs#L20-L28); [crates/openhuman-core/src/config/schema/observability.rs:103-108](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/observability.rs#L103-L108) (verified)
  - *To reach the next level:* Make content telemetry opt-in.
- **B L1:** The agent holds long-lived account credentials and connected-app grants with write scope. — [crates/openhuman-core/src/integrations/composio/contract/scopes.rs:106-113](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/integrations/composio/contract/scopes.rs#L106-L113); [crates/openhuman-core/src/security/keyring/backend.rs:38-45](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/keyring/backend.rs#L38-L45) (verified)
  - *To reach the next level:* Scoped, short-lived credentials.
- **Cap:** none

### C9 Audit & traceability — 0.40 (high)

Agent runs are journaled as structured events with run ids, approvals and their outcomes are kept in a SQLite table, and shell commands are appended with fsync to an audit log. The journal is best-effort, sub-agent lineage is only partly threaded, and everything lives under the user's OpenHuman directory, where the in-process file tools can write when the autonomy policy is disabled.

- **S L2:** Structured run journal with stable event ids, plus a JSON audit line per shell command. — [crates/openhuman-core/src/agent/tinyagents/journal.rs:193-198](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/journal.rs#L193-L198); [crates/openhuman-core/src/tools/impl/system/shell.rs:132-140](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L132-L140) (verified)
  - *To reach the next level:* Actor attribution separating agent, requester and approver, with correlation across sub-agents.
- **C L2:** Built-in tool calls reach the journal; the separate audit log records only shell commands and sub-agent lineage is incomplete. — [crates/openhuman-core/src/tools/impl/system/shell.rs:132-140](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L132-L140); [crates/openhuman-core/src/agent/tinyagents/journal.rs:38-43](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/journal.rs#L38-L43) (verified)
  - *To reach the next level:* All tool calls including extensions and sub-agents, plus approvals and denials in one record.
- **D L1:** On by default but stored in the workspace directory that agent file tools can modify while containment is disabled. — [crates/openhuman-core/src/config/schema/channels.rs:73-75](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/config/schema/channels.rs#L73-L75); [crates/openhuman-core/src/security/policy/path_checks.rs:63-74](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/security/policy/path_checks.rs#L63-L74) (verified)
  - *To reach the next level:* Records written where the agent's own tools cannot reach.
- **B L1:** Journal writes are best-effort and failures are logged and ignored; audit write failures do not stop the action. — [crates/openhuman-core/src/agent/tinyagents/journal.rs:13-16](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/journal.rs#L13-L16); [crates/openhuman-core/src/tools/impl/system/shell.rs:120-123](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L120-L123) (verified)
  - *To reach the next level:* Errors surfaced with records flushed per action.
- **Cap:** none

### C10 Limits & kill switch — 0.40 (high)

The default agent stops after 200 model iterations and most tools time out after 120 seconds, and delegation is capped at three levels. There is no cost or token cap in the default path: the cost middleware only observes. Shell and other scripting tools have no default timeout, the model chooses its own via timeout_secs, and an unsandboxed shell command that outlives its timeout is not killed.

- **S L2:** Iteration cap plus per-tool timeouts are enforced in code; no token or cost cap. — [crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml:9](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml#L9); [crates/openhuman-core/src/tools/timeout/mod.rs:22](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/timeout/mod.rs#L22); [crates/openhuman-core/src/agent/tinyagents/middleware/cost_budget.rs:11-16](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/middleware/cost_budget.rs#L11-L16) (verified)
  - *To reach the next level:* Enforced token or cost caps with every step kind bounded in time.
- **C L2:** The loop cap and most tool timeouts apply, with a delegation depth cap. — [crates/openhuman-core/src/agent/harness/spawn_depth_context.rs:42](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/harness/spawn_depth_context.rs#L42); [crates/openhuman-core/src/agent/tools/run_workflow.rs:271-278](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tools/run_workflow.rs#L271-L278) (verified)
  - *To reach the next level:* Sub-agents and background runs counted against one shared budget.
- **D L1:** Defaults are large (200 iterations, unbounded shell) and the model can lift the shell deadline by passing timeout_secs. — [crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml:9](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/registry/agents/orchestrator/agent.toml#L9); [crates/openhuman-core/src/tools/impl/system/shell.rs:235-240](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L235-L240); [crates/openhuman-core/src/tools/timeout/mod.rs:36](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/timeout/mod.rs#L36) (verified)
  - *To reach the next level:* Sensible defaults the model cannot raise.
- **B L1:** Fire-and-forget workflow runs continue independently, and a timed-out unsandboxed command keeps running. — [crates/openhuman-core/src/tools/impl/system/shell.rs:439-442](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/tools/impl/system/shell.rs#L439-L442); [crates/openhuman-core/src/agent/tinyagents/host/budget_gate.rs:13-15](https://github.com/tinyhumansai/openhuman/blob/cbde5069dec828c117131ee75f9d2bbeb5bda02b/crates/openhuman-core/src/agent/tinyagents/host/budget_gate.rs#L13-L15) (verified)
  - *To reach the next level:* Stop that cancels pending calls and leaves nothing running.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Web fetch and search results, connected-app data, MCP tool results and recalled memory screened only by heuristics (crates/openhuman-core/src/agent/tinyagents/host/security_gate.rs:634) · [B] sensitive data/systems: User home directory outside credential stores and long-lived account and connected-app grants (crates/openhuman-core/src/security/policy/path_checks.rs:63, crates/openhuman-core/src/integrations/composio/contract/scopes.rs:106) · [C] state change / egress: Unprompted shell, file-write and HTTP calls with fetch allowed to any public host (crates/openhuman-core/src/security/policy/command_checks.rs:164, crates/openhuman-core/src/config/schema/tools/http.rs:32) · Same default session? Yes

## Highest-impact improvements
1. Ship [autonomy] enabled = true in Supervised mode so shell, file-write and network calls are classified and parked for approval by default. — C2 C L0→L2, +0.150 before caps (Playbook 5)
2. Make content capture in usage-data sharing opt-in, sending metadata-only spans unless the user enables content. — C8 D L0→L2, +0.100 before caps (Playbook 4)
3. Once untrusted content is in the session, require approval for network egress and writes even when the autonomy policy is off. — C5 B L0→L2, +0.100 before caps (Playbook 1)
4. Route cron shell jobs, MCP stdio servers and agents without a declared sandbox through the jail, and refuse to run when no jail is available. — C4 C L1→L3, +0.150 before caps (Playbook 3)
5. Add a default per-run cost or token cap and a default shell timeout that the model cannot lift. — C10 D L1→L2, +0.050 before caps (Playbook 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- Much of the runtime lives in git submodules (tinyagents, tinytools, tinybox, tinymcp, tinychannels and others). tinyagents, tinybox and tinymcp were read at their pinned revisions for context, but citations are limited to files in this repository, so the C7 environment-inheritance rating is marked inferred.
- Messaging channels (tinychannels), the Tauri desktop shell and the web frontend were not reviewed in depth; channel sender allowlists live in a submodule.
- The CLI host loads a .env file from the working directory at startup; the desktop app was scored as the primary mode.
- The jail's behaviour per platform (Landlock reads restricted, Seatbelt reads open, Windows unconfined) was taken from the vendored tinybox-jail source at its pinned revision.
- No text aimed at AI reviewers was found in README, AGENTS.md, CLAUDE.md or SECURITY.md.
