Skip to content

Security and Privacy

Shivang edited this page Oct 5, 2026 · 2 revisions

Security and privacy

BossConsole provides controls over tools used through BOSS. These controls do not govern every action an external agent can take outside those tools.

Tool access and approvals

  • Tool exposure: per-tool switches in Toolbox remove disabled tools from the exposed inventory.
  • Account access: roles and permissions affect which plugins and tools are available. Administrators can bypass role permission checks, but not tool kill-switches.
  • Governed invocation: tool policies, session trust, and approvals decide whether a call proceeds. Explicit denials remain authoritative.
  • Revocation: removing access prevents future authorization; it does not cancel work already authorized.

See Agents and MCP for the management surfaces.

Stored credentials

Supported browser autofill and governed secret references can deliver a stored value directly to the approved tool/destination without routinely placing it in the model's context. Secret-bearing governed calls require approval even under YOLO mode.

This is a model-facing non-disclosure property, not a promise that an authorized tool or destination cannot forward the value. An explicit secret-reading tool can return a value when authorized. Installed plugins can access host capabilities according to their integration; in-process plugin code is not an OS sandbox.

The precise contract and limitations are in MCP secret references.

Sharing

Terminal and BossConsole window sharing are separate protocols. The application-window protocol encrypts video and control payloads above the transport, so the SFU relay forwards encrypted media rather than readable window pixels. The BOSS account backend is trusted for admission and media-key delivery; it is not excluded from the trust model.

Window sharing is restricted to the signed-in account and registered BossConsole windows. Same-account admission and control default to enabled, with settings to turn them off. Control is held by one device at a time and checked against a current lease. Guest access is not enabled for application sharing.

The versioned application-sharing protocol is experimental; the implementation does not claim an independent cryptographic audit or SFrame interoperability. See the media protocol documentation.

Plugin trust

Store signatures bind a plugin's identity, version, and content. Verify the publisher and the capabilities you enable. A signed plugin is not automatically safe, and plugin terms may differ from the core application's Apache-2.0 license.

Report a vulnerability

Email security@risalabs.ai with a description, reproduction steps, and impact. Do not publish sensitive exploit details in a public issue. The repository's security policy is authoritative.


Continue: Home · ← Development and contributing · Troubleshooting →

Clone this wiki locally