Security

Report it. We'll fix it.

If you find a vulnerability in CommandAGI, tell us privately first. We read every report and we reply.

Reporting a vulnerability

Email security@commandagi.com. Please include:

  • what you found, and where (a URL, an API route, a package or a file);
  • the steps to reproduce it, and what an attacker could do with it;
  • how to reach you, and whether you would like to be credited.

Give us a reasonable time to fix the problem before you disclose it. Do not access other people's data beyond what you need to show the problem, do not degrade the service, and never send commands to a machine you do not own.

In scope

  • commandagi.com, developers.commandagi.com and api.commandagi.com
  • the desktop app and the local host it runs
  • the commandagi packages on npm and PyPI

Machine-readable contact details are at /.well-known/security.txt.

By design

How the product protects itself.

Authority is a person's act

Only a person creates or widens a grant. An agent key cannot grant itself, or another agent, anything.

Principals are proven

A principal acts with a credential, never by naming itself. The host keeps only the credential's hash.

Recorded before sent

Every action on a machine is written to its run, with who sent it, before the driver is called.

Secrets stay out of files

Connection secrets live in the host's secret store or in memory — never in a world, a definition, settings, a stream or a log line.

Loopback by default

The local host listens on 127.0.0.1 only, and its control endpoints refuse requests that come from a web page.

Keys are hashed

API keys are stored as hashes, never as the key itself.