Back to Overview
SECURITY POLICY & THREAT MODEL

Security & Privacy by Design

Giving an AI agent access to your terminal, filesystem, and browser requires defense-in-depth safeguards. OpenAgent is architected with strict fail-closed boundaries.

1. Strict Fail-Closed Safe Mode

When `BRIDGE_SAFE_MODE=true` (the default), OpenAgent continuously asserts that the WhatsApp Desktop window matches your configured assistant number (`BRIDGE_WHATSAPP_NUMBER`). If the conversation shifts, execution halts immediately.

2. Offline Wake-Word Detection

Idle audio never leaves your Mac. Vosk processes microphone buffers locally on device. No audio recording or transmission occurs until the wake phrase ("Wake up, Jarvis") is recognized.

3. Atomic Exact-Match Edits

The `edit` tool requires exact chunk string matches before replacing code. If source code has diverged, the edit aborts and returns a unified diff error rather than guessing or corrupting files.

4. Anti-Duplication Ledger

Every social action, reply, upvote, and post URL is hashed and checked against `operation-log.json`. OpenAgent prevents duplicate loops, spamming, and rate-limit violations automatically.

AI Computer-Use Responsibility

OpenAgent performs actions with the privileges of your local user account on macOS. Never run an autonomous computer-use agent in an environment where unintended actions could cause unrecoverable loss. Keep confidential tokens out of direct working directories, verify macOS TCC permissions, and inspect `.env` configurations.

Reporting a Vulnerability

We take the security of OpenAgent seriously. If you discover a potential vulnerability, please do not disclose it via public GitHub issues.

1. Open a private GitHub Security Advisory in the repository.

2. Provide clear reproduction steps and impact description.

3. Maintainers acknowledge reports promptly and coordinate responsible patches.