BoundBench

Vibe Kanban

Local kanban web app that plans tasks and runs coding-agent CLIs (Claude Code, Codex, Gemini CLI, Amp, Cursor, Copilot and others) in per-task git worktrees, with diff review and PR creation.

github.com/BloopAI/vibe-kanban · 2026-10-05 · d5cbb53

Defense-in-depth score

1.2 / 10

Minimal

Vibe Kanban launches every coding agent with its permission prompts switched off by default (Claude Code with --dangerously-skip-permissions, Codex with full access, Gemini and Qwen in yolo mode) and runs it unsandboxed on the host with the user's full environment. A prompt injection in a repository, issue or web page can make an agent read credentials, push code and send data out with no human involved. Each task gets its own git worktree and branch, which keeps file changes reviewable, and a per-call approval mode exists, but it is opt-in, covers only some agents, and is not tamper-resistant.

Key gaps (7)

  1. Agents run with the user's full inherited environment and CLI logins and no scoped identity, so a hijacked agent holds the user's whole account. C1 · Identity & least privilege
  2. Every shipped agent profile disables the agent's permission prompts, so shell commands run with no approval by default. C2 · Approval gates
  3. The opt-in approval mode does not protect its own configuration from the agent, so the model can widen its permissions without a human. C2 · Approval gates
  4. Agents and scripts run on the host as the user with no sandbox and the full credential-bearing environment. C4 · Code-execution isolation
  5. In the default configuration a prompt-injected agent can exfiltrate secrets and take irreversible actions with no human in the loop. C5 · Untrusted input blast radius
  6. Repository-controlled instruction and settings files load into agents launched with prompts disabled, with no workspace-trust decision. C6 · Memory, context & configuration integrity
  7. Agent CLIs and MCP servers are fetched through npx (some at @latest) and run as the user with the full environment. C7 · Third-party extensions

Criteria

C1 Identity & least privilege

Minimal 0.00 / 1.00

Every coding agent runs as the desktop user with the server's full inherited environment, plus the user's own CLI logins (Claude, gh, az, SSH), and Vibe Kanban adds no scoped identity or authorization layer between the agent and those credentials. Pull requests are created with the user's gh or az CLI login. A hijacked agent therefore holds everything the user can reach.

C2 Approval gates

Minimal 0.25 / 1.00

Every shipped agent profile turns the agent's own permission prompts off by default: Claude Code gets --dangerously-skip-permissions, Codex runs with full access, and Gemini and Qwen run in yolo mode. The docs describe this setting as removing safety guardrails. An opt-in 'Ask' mode routes each non-read tool call to an approval card in the UI that shows the call and denies on timeout. It covers only five of the nine agents (the others auto-approve), and a request without a tool ID is allowed through, as a source comment notes. The approval configuration is not tamper-resistant against the agent. Each task runs on its own branch in a separate git worktree, so file changes can be reviewed before merging, but shell side effects, pushes and external calls cannot be undone.

C3 Tool & action scoping

Minimal 0.00 / 1.00

The consequential tools are the agent runtimes' own general-purpose ones (shell, file write, web fetch), passed through with no extra argument validation by Vibe Kanban, and the default profiles switch off the runtimes' own restrictions (for example Codex's workspace-write sandbox). The agent starts in a per-task git worktree, but nothing stops it from reaching outside it. Vibe Kanban's own MCP tools are typed but opt-in. A misused tool can reach the whole machine.

C4 Code-execution isolation

Minimal 0.00 / 1.00

Agents, and the setup, cleanup and dev-server scripts, run as ordinary processes of the desktop user on the host, with the full inherited environment. Vibe Kanban ships no container or OS sandbox, and its default Codex profile turns off Codex's own sandbox. Per-task git worktrees separate the files but are not an isolation boundary. Model-written commands can reach the user's whole home directory, credentials and network.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

Agents read repository files (with CLAUDE.md and AGENTS.md imported automatically), web content through their own tools, and issue text from the kanban board, with no provenance marking or detection in Vibe Kanban. Because permission prompts are off and the agent holds the user's credentials and network access, injected content can make it exfiltrate secrets and push or delete with no human involved.

C6 Memory, context & configuration integrity

Minimal 0.10 / 1.00

Agents run in a worktree of the user's repository with their permission prompts disabled, and Vibe Kanban writes workspace CLAUDE.md and AGENTS.md files that import the repository's own instruction files. Vibe Kanban has no workspace-trust decision of its own, so repository-controlled agent settings, hooks and MCP definitions are left to runtimes that have been told not to ask. Agent sessions are resumed across turns. With the opt-in Vibe Kanban MCP server, an agent can also rewrite the setup and dev-server scripts that run in later workspaces.

C7 Third-party extensions

Minimal 0.20 / 1.00

The agent CLIs themselves are downloaded and run through npx at launch, most at pinned versions but Amp at @latest, with no integrity check beyond npm's. The built-in MCP catalog adds servers with unpinned or @latest npx commands, written to the user's agent configuration after an explicit add. Cursor's user-scope MCP servers are pre-approved for each worktree. Every extension runs as the user with the full environment.

C8 Secrets & sensitive-data protection

Minimal 0.20 / 1.00

Vibe Kanban's own cloud login is stored in a file readable only by the user, but agents and scripts receive the whole inherited environment, including any API keys and tokens, and nothing is redacted in stored agent logs. Error reporting to Sentry is initialised at startup in release builds without a consent check, with log lines attached as breadcrumbs, and product analytics are on until the user opts out. A leaked key is typically long-lived and broad.

C9 Audit & traceability

Minimal 0.45 / 1.00

Every agent and script run is recorded as an execution process, and the agent's raw structured output, including tool calls, results and approval requests and responses, is appended line by line to a JSONL file in the app's data directory outside the workspace. The record is written by the same user the agent runs as, so the agent could alter it, and a failure to open the log file is only logged while the run continues. There is no actor attribution beyond the session and no tamper evidence.

C10 Limits & kill switch

Minimal 0.00 / 1.00

Vibe Kanban sets no turn, time or cost limit on agent runs, and the runtimes are launched without their own turn caps. The stop button works well: it signals the agent's whole process group with SIGINT, then SIGTERM, then SIGKILL. Nothing bounds how long or how much a runaway agent can spend before someone presses it.