Repository navigation
v0.2.3 — Security Hardening
Security — 10 Vulnerabilities Fixed
A security audit identified 10 vulnerabilities in the hook-based permission system. All have been fixed.
Critical (4): Hook overwrite via Bash, hook overwrite via Write/Edit, agent escalation via Bash (spawn claude as Supervisor), symlink bypass for writes outside ~/Builds/
High (3): NotebookEdit bypassed write gate, missing trailing slash in path prefix check, unknown agent identity got permissive defaults
Medium (2): WebFetch data exfiltration risk, jq parse failure fell through to allow
Low (1): Path traversal via .. components
Design changes:
- Catch-all default changed from ALLOW to DENY
- Agent S restricted — writes jailed to ~/Builds/, reads unrestricted
- Agent tool blocked for all agents including S
- Added SECURITY.md with full vulnerability details and current permission matrix
See SECURITY.md for the complete report.