Skip to content

Security: HelloHaoWu/Codexification

Security

docs/SECURITY.md

Security contract

Process execution

All runtime calls use spawn/spawnSync with shell: false. Model-controlled input is represented as argv entries or parsed JSON; it is never interpolated into a shell command. Binary override variables must contain absolute executable paths.

Controller ownership

agent-browser owns web content by default. Open Computer Use owns native applications, system dialogs, and browser chrome. The suite does not automatically fall back from one controller to the other because such fallback could bypass approval or operate a different session.

The browser-chrome obstruction guard is read-only and targets only the isolated Google Chrome for Testing application. It never inspects the user's personal Chrome. On macOS, the launcher enforces the non-sensitive TranslateEnabled=false policy in Chrome for Testing's dedicated com.google.ChromeForTesting preferences domain before launch; the com.google.Chrome domain used by the user's personal browser is never modified. Dismissal remains an explicit Open Computer Use action under the Desktop permission boundary. Browser auto-approval never implies Desktop approval.

When ownership changes:

  1. Identify the target window, session, and current URL.
  2. Stop concurrent actions.
  3. Invalidate prior browser refs and desktop indexes.
  4. Read fresh state before the next mutation.

Protected data

Compression must retain, byte-for-byte, all discovered:

  • @eN references and element_index markers.
  • call, tool-call, session, tab, and CDP target identifiers.
  • URLs and content hashes.
  • Tool schemas, action parameters, approval decisions, and error codes.

Adapters scan compressed output for protected tokens. Any mismatch rejects the optimized projection and retains the original result. This check is a safety floor, not a proof that arbitrary semantic content was preserved.

Permissions

  • Pi prompts before mutating desktop actions.
  • DSH actions remain inside its native tool approval/policy pipeline.
  • Claude Code delegates plugin MCP approvals to its native per-server approval flow.
  • A denial in one transport applies to equivalent actions in every other transport.

Sensitive local state

Cookies, profiles, screenshots, Accessibility trees, and Headroom retrieval content remain in their upstream runtimes. The installer ledger records no such data. Operators remain responsible for upstream retention settings and OS-level Accessibility/Screen Recording permissions.

Authentication handoff is a narrow exception to the normal no-focus and end-of-response cleanup rules. It is allowed after a strong value-free runtime signal identifies an authentication challenge, or after the Agent confirms a weaker challenge blocks the requested browser task. The lease is atomically written with mode 0600, expires after 30 minutes by default, identifies only the suite-owned Harness/session/profile/tab/process, and stores a non-secret resume goal. It never stores form values, passwords, one-time codes, recovery codes, cookies, access tokens, Authorization headers, screenshots, or page text.

On macOS the handoff matches the complete ordered tab URL sequence in exactly one com.google.chrome.for.testing window, selects it in the background, and sends a generic native system notification containing no site, lease, or credential data. The preferred sender is the background-launched Codexification app so the notification can use its bundled icon; /usr/bin/osascript is the no-asset fallback. Notification text never receives the lease path, PID, nonce, URL, or page content. The notification is reminder-only and cannot activate Chrome. A later explicit Harness request to open the login page rereads the private lease, verifies expiration, tab identity, profile ownership, and the exact main PID before using AppKit. Activation is accepted only when the operating system reports that PID as frontmost. Notification denial, Focus mode suppression, ambiguous ownership, a missing process, a missing tab, an expired lease, or an unsupported platform never triggers an automatic foreground fallback. Wake-up checks select the tab in the background and never reactivate the app. Session shutdown clears the lease and closes the suite-owned browser.

There aren't any published security advisories