Skip to content

v0.2.3 — Security Hardening

Choose a tag to compare

@johnkf5-ops johnkf5-ops released this 02 Apr 02:25
· 52 commits to main since this release

Security — 10 Vulnerabilities Fixed

A security audit identified 10 vulnerabilities in the hook-based permission system. All have been fixed.

Critical (4): Hook overwrite via Bash, hook overwrite via Write/Edit, agent escalation via Bash (spawn claude as Supervisor), symlink bypass for writes outside ~/Builds/

High (3): NotebookEdit bypassed write gate, missing trailing slash in path prefix check, unknown agent identity got permissive defaults

Medium (2): WebFetch data exfiltration risk, jq parse failure fell through to allow

Low (1): Path traversal via .. components

Design changes:

  • Catch-all default changed from ALLOW to DENY
  • Agent S restricted — writes jailed to ~/Builds/, reads unrestricted
  • Agent tool blocked for all agents including S
  • Added SECURITY.md with full vulnerability details and current permission matrix

See SECURITY.md for the complete report.

Full Changelog

v0.2.2...v0.2.3