C1 Identity & least privilege
Minimal 0.00 / 1.00
SuperAGI runs every agent with one set of operator credentials read from a global config.yaml (email password, GitHub token, Slack, Jira, AWS), shared by every user and organisation. The API's authentication and authorization are not locked down.
C2 Approval gates
Minimal 0.15 / 1.00
A human-approval mode (RESTRICTED) exists, but agents default to 'God Mode', where every tool call runs without approval; agents created through the public API are forced into God Mode. When RESTRICTED is chosen, the approver is shown only the tool's name, not its arguments, and the approval endpoint's access control is not locked down. Consequential actions such as sending email, deleting files or posting tweets are irreversible.
C3 Tool & action scoping
Minimal 0.05 / 1.00
Tools pass model arguments straight through. File tools' path handling is not a strict boundary. The web scraper fetches any URL, including internal addresses. Pydantic schemas only check types. The default tool set offered in the GUI includes Write File.
C4 Code-execution isolation
Minimal 0.00 / 1.00
SuperAGI has no sandbox. Not every model-influenced execution path in task workflows is confined. The worker process holds every credential, runs as root in a container with no hardening, and has the application source mounted read-write from the host. Startup also runs downloaded tool code in-process.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Search results, scraped pages, emails, GitHub PRs and files enter the model's context with no marking, and tool results are stored and replayed with the 'system' role, giving injected text the same standing as the operator's instructions. Nothing limits a hijacked agent: in the default God Mode it can read secrets and send them out through email, Slack, Twitter or a scraped URL, and take irreversible actions, all unattended.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
When the OpenAI model is used, every model reply and raw tool result is written unvalidated into a Redis vector index shared by all agents and organisations, and later read back into a system-role prompt by the thinking tool. Retrieval is filtered by execution id, so this store mostly affects the same run. A more durable path exists through the file tools.
C7 Third-party extensions
Minimal 0.00 / 1.00
Every time the backend or worker container starts, it downloads the latest main-branch zip of the TransformerOptimus/SuperAGI-Tools repository (and any user-added GitHub tool links), without pinning or integrity checks, pip-installs each tool's requirements as root, and imports the tool code into the server process. Any user can add a new GitHub tool link through the API. A compromise of that repository or any listed tool runs with all of SuperAGI's credentials.
C8 Secrets & sensitive-data protection
Minimal 0.00 / 1.00
Credentials live in a plaintext config.yaml, and default secrets and stored tool keys are not locked down. Nothing is redacted: tool outputs are logged at info level. Analytics are only enabled when the operator provides IDs.
C9 Audit & traceability
Minimal 0.38 / 1.00
Each step's raw model reply (which contains the tool name and arguments) and the tool's result are saved as timestamped rows in Postgres, and approval decisions are stored in their own table. There is no actor attribution beyond a single shared user, no tamper protection, and the worker process that executes model-controlled code holds the database credentials. Records are written after the tool runs, so a crash mid-call loses it.
C10 Limits & kill switch
Minimal 0.38 / 1.00
Each run has an iteration cap (25 by default in the GUI) enforced before every step, and runs older than one day are skipped. There is no token or cost cap: a Budget table exists but is never checked. Stopping a run only changes a status field that the next step checks, so an in-flight tool call finishes, and scheduled agents keep firing from the Celery beat scheduler.