Skip to content

Security and Privacy

gysosin edited this page Oct 8, 2026 · 1 revision

Security and privacy

What stays on your machine

  • The tracker, generated CVs and letters, application folders, Gmail state, replies and run logs. All are git-ignored.
  • Secrets: the dashboard login hash and the Gmail app password, in ~/.config/applydesk/config.json (mode 600), outside the repo.
  • What leaves your machine: job-site requests during a search, Gmail IMAP reads, Claude API calls (posting text, your profile, email text), and ntfy pushes if you turn them on.

What the AI agents can and cannot do

Every tool call passes app/guards.py first:

  • No browser or form tools: agents cannot submit applications or log in anywhere.
  • No git, no shell substitution or multi-line commands; curl is GET only with an allowlist of flags.
  • Writes only to cv/, cover_letters/, documents/applications/ and company_research/.
  • Reads only inside the project folder, never app/data, .git, .venv or .env files, so secrets in ~/.config or ~/.ssh are out of reach.

LaTeX written by an agent compiles only through app/texc.py inside bubblewrap: no network, home directory hidden, only the document folder writable, TeX file I/O set to paranoid.

Untrusted input

Job postings and emails can contain instructions aimed at an AI. Every prompt treats them as data, never instructions; agents never fetch URLs found inside a posting, and company facts are verified from sources the agent finds itself.

The dashboard

  • Single user, salted PBKDF2 password hash.
  • HttpOnly, SameSite=Strict session cookie (Secure over HTTPS); an origin check on state-changing requests.
  • Listens on 127.0.0.1 by default. Opening it wider (--host 0.0.0.0, a proxy, a tunnel) is your call: use HTTPS and a strong password.

Keeping your copy private

/setup writes your personal details into tracked files (CLAUDE.md, the profile). A GitHub fork is always public, so keep your real job search in a private repository, or don't push those files at all.

Reporting a vulnerability

Use private vulnerability reporting. See SECURITY.md.

Clone this wiki locally