Skip to content

Security: RaulMermans/Open-VS-Code-Agent

Security

SECURITY.md

Security

This repository

This is documentation plus type-only contracts. It contains no agent runtime, no prompts, no credentials, no configuration files and no private code. The traces are synthetic, and the benchmark aggregates contain no task content.

The system it describes

  • Local-first. Inference runs on the developer's machine, and code doesn't leave it.
  • Least privilege by mode. ASK, PLAN and REVIEW are read-only. Mutation and verification require human approval.
  • No free-form shell. Only declared tools run, and verification is limited to discovered project scripts.
  • Path safety. Workspace containment, symlink-escape rejection, and time-of-check/time-of-use protection on writes.
  • Stale-base guard. A patch applies only if the file still matches the content it was written against.
  • Write-ahead durability. No side effect happens without a prior durable record; if the record can't be written, execution stops.
  • Approvals don't survive restarts, so an approval can't be replayed.
  • Untrusted input. Repository content and MCP tool descriptions are treated as data. MCP schemas are size-bounded.
  • Secrets. Secret-like values are kept out of model context and logs.

Reporting

If you believe something here exposes sensitive information, please open a private security advisory on this repository instead of a public issue.

There aren't any published security advisories