Worker security
The worker is a sensitive execution boundary. How its local API, credentials, project isolation, environment, command execution, Git and OS sandbox are protected.
Local UI and API
Bound to 127.0.0.1 by default. It requires a per-worker token, rejects foreign Host headers (DNS rebinding)
and refuses CORS preflights.
Credentials
Stored in the OS credential store (encrypted-file fallback), never in plaintext configuration.
Project isolation
Agents run only inside mapped project paths; path traversal and symlink escapes are rejected.
Environment
Agents receive an allow-listed environment plus the selected provider's credential. Unrelated secrets in the
worker's environment (for example GITHUB_TOKEN) are not passed on. Tasks that target an environment profile
receive that profile's variables and referenced secrets, sent only for that task and audited by name; their
values are removed from recorded output.
Command execution
Argument arrays with shell: false; Windows .cmd shims are validated so arguments cannot inject commands.
Prompts go through stdin or files, never the command line.
Git
Force-push, reset --hard, clean, branch deletion and discarding changes are refused. Pre-existing uncommitted
work is never committed.
OS sandbox (policy sandbox)
| Mode | Behaviour |
|---|---|
off (default) | No sandbox |
preferred | Sandbox where the worker has one; otherwise run and note it in the recovery notes |
required | A worker without a sandbox stops the task with RECOVERY_REQUIRED |
Linux uses bubblewrap and macOS sandbox-exec. The whole file system stays readable, but writes are allowed only
to the project, temporary folders and the agent's state folders (~/.claude, ~/.codex, ~/.cache …). ~/.ssh,
~/.gnupg, ~/.netrc, ~/.git-credentials, ~/.docker, ~/.kube, ~/.azure, ~/.password-store and the
worker's data folder are hidden. network: false also cuts network access. writable and hidden add paths.
Workers with a sandbox advertise the os-sandbox tool, so a task can require one.
Known gaps
The sandbox is off by default, is not available on Windows, and has been verified only with a stand-in for bubblewrap. Without it, agents run with the user's permissions, and enforcement relies on the agent's own permission mode plus the project-path and environment controls above.
Plugins
Plugins run in a separate Node.js process under the permission model, with only the permissions they declare, no inherited environment, and time and memory limits. The worker's owner can untick Run approved plugin code on this machine. See Plugins.