Security & Privacy by Design
Giving an AI agent access to your terminal, filesystem, and browser requires defense-in-depth safeguards. OpenAgent is architected with strict fail-closed boundaries.
1. Strict Fail-Closed Safe Mode
When `BRIDGE_SAFE_MODE=true` (the default), OpenAgent continuously asserts that the WhatsApp Desktop window matches your configured assistant number (`BRIDGE_WHATSAPP_NUMBER`). If the conversation shifts, execution halts immediately.
2. Offline Wake-Word Detection
Idle audio never leaves your Mac. Vosk processes microphone buffers locally on device. No audio recording or transmission occurs until the wake phrase ("Wake up, Jarvis") is recognized.
3. Atomic Exact-Match Edits
The `edit` tool requires exact chunk string matches before replacing code. If source code has diverged, the edit aborts and returns a unified diff error rather than guessing or corrupting files.
4. Anti-Duplication Ledger
Every social action, reply, upvote, and post URL is hashed and checked against `operation-log.json`. OpenAgent prevents duplicate loops, spamming, and rate-limit violations automatically.
OpenAgent performs actions with the privileges of your local user account on macOS. Never run an autonomous computer-use agent in an environment where unintended actions could cause unrecoverable loss. Keep confidential tokens out of direct working directories, verify macOS TCC permissions, and inspect `.env` configurations.
Reporting a Vulnerability
We take the security of OpenAgent seriously. If you discover a potential vulnerability, please do not disclose it via public GitHub issues.
1. Open a private GitHub Security Advisory in the repository.
2. Provide clear reproduction steps and impact description.
3. Maintainers acknowledge reports promptly and coordinate responsible patches.