C1 Identity & least privilege
Minimal 0.00 / 1.00
Every coding agent runs as the desktop user with the server's full inherited environment, plus the user's own CLI logins (Claude, gh, az, SSH), and Vibe Kanban adds no scoped identity or authorization layer between the agent and those credentials. Pull requests are created with the user's gh or az CLI login. A hijacked agent therefore holds everything the user can reach.
C2 Approval gates
Minimal 0.25 / 1.00
Every shipped agent profile turns the agent's own permission prompts off by default: Claude Code gets --dangerously-skip-permissions, Codex runs with full access, and Gemini and Qwen run in yolo mode. The docs describe this setting as removing safety guardrails. An opt-in 'Ask' mode routes each non-read tool call to an approval card in the UI that shows the call and denies on timeout. It covers only five of the nine agents (the others auto-approve), and a request without a tool ID is allowed through, as a source comment notes. The approval configuration is not tamper-resistant against the agent. Each task runs on its own branch in a separate git worktree, so file changes can be reviewed before merging, but shell side effects, pushes and external calls cannot be undone.
C3 Tool & action scoping
Minimal 0.00 / 1.00
The consequential tools are the agent runtimes' own general-purpose ones (shell, file write, web fetch), passed through with no extra argument validation by Vibe Kanban, and the default profiles switch off the runtimes' own restrictions (for example Codex's workspace-write sandbox). The agent starts in a per-task git worktree, but nothing stops it from reaching outside it. Vibe Kanban's own MCP tools are typed but opt-in. A misused tool can reach the whole machine.
C4 Code-execution isolation
Minimal 0.00 / 1.00
Agents, and the setup, cleanup and dev-server scripts, run as ordinary processes of the desktop user on the host, with the full inherited environment. Vibe Kanban ships no container or OS sandbox, and its default Codex profile turns off Codex's own sandbox. Per-task git worktrees separate the files but are not an isolation boundary. Model-written commands can reach the user's whole home directory, credentials and network.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Agents read repository files (with CLAUDE.md and AGENTS.md imported automatically), web content through their own tools, and issue text from the kanban board, with no provenance marking or detection in Vibe Kanban. Because permission prompts are off and the agent holds the user's credentials and network access, injected content can make it exfiltrate secrets and push or delete with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
Agents run in a worktree of the user's repository with their permission prompts disabled, and Vibe Kanban writes workspace CLAUDE.md and AGENTS.md files that import the repository's own instruction files. Vibe Kanban has no workspace-trust decision of its own, so repository-controlled agent settings, hooks and MCP definitions are left to runtimes that have been told not to ask. Agent sessions are resumed across turns. With the opt-in Vibe Kanban MCP server, an agent can also rewrite the setup and dev-server scripts that run in later workspaces.
C7 Third-party extensions
Minimal 0.20 / 1.00
The agent CLIs themselves are downloaded and run through npx at launch, most at pinned versions but Amp at @latest, with no integrity check beyond npm's. The built-in MCP catalog adds servers with unpinned or @latest npx commands, written to the user's agent configuration after an explicit add. Cursor's user-scope MCP servers are pre-approved for each worktree. Every extension runs as the user with the full environment.
C8 Secrets & sensitive-data protection
Minimal 0.20 / 1.00
Vibe Kanban's own cloud login is stored in a file readable only by the user, but agents and scripts receive the whole inherited environment, including any API keys and tokens, and nothing is redacted in stored agent logs. Error reporting to Sentry is initialised at startup in release builds without a consent check, with log lines attached as breadcrumbs, and product analytics are on until the user opts out. A leaked key is typically long-lived and broad.
C9 Audit & traceability
Minimal 0.45 / 1.00
Every agent and script run is recorded as an execution process, and the agent's raw structured output, including tool calls, results and approval requests and responses, is appended line by line to a JSONL file in the app's data directory outside the workspace. The record is written by the same user the agent runs as, so the agent could alter it, and a failure to open the log file is only logged while the run continues. There is no actor attribution beyond the session and no tamper evidence.
C10 Limits & kill switch
Minimal 0.00 / 1.00
Vibe Kanban sets no turn, time or cost limit on agent runs, and the runtimes are launched without their own turn caps. The stop button works well: it signals the agent's whole process group with SIGINT, then SIGTERM, then SIGKILL. Nothing bounds how long or how much a runaway agent can spend before someone presses it.