BoundBench

SuperAGI

Open-source autonomous agent platform with a web GUI, tool marketplace, workflows and scheduled agents.

github.com/transformeroptimus/superagi · 2026-10-04 · c3c1982

Defense-in-depth score

1.1 / 10

Minimal

As shipped, SuperAGI has essentially no safety boundary: agents default to 'God Mode' with no approval, every agent uses the operator's global email, GitHub and chat credentials, and every container start downloads and runs unpinned third-party tool code. The API's access control is also not locked down, model output in task workflows is not confined, and the file tools' path handling is not a strict boundary. A single prompt injection from a search result or email can exfiltrate secrets and take irreversible actions unattended.

Key gaps (3)

  1. A hijacked agent in default God Mode can exfiltrate secrets and take irreversible actions (email, tweets, GitHub deletes) with no human involved. C5 · Untrusted input blast radius
  2. Every container start downloads unpinned main-branch tool code from GitHub, pip-installs its requirements and imports it in-process with no integrity check. C7 · Third-party extensions
  3. Every agent uses global operator credentials with write access to multiple external systems; API access control is not locked down. C1 · Identity & least privilege

Criteria

C1 Identity & least privilege

Minimal 0.00 / 1.00

SuperAGI runs every agent with one set of operator credentials read from a global config.yaml (email password, GitHub token, Slack, Jira, AWS), shared by every user and organisation. The API's authentication and authorization are not locked down.

C2 Approval gates

Minimal 0.15 / 1.00

A human-approval mode (RESTRICTED) exists, but agents default to 'God Mode', where every tool call runs without approval; agents created through the public API are forced into God Mode. When RESTRICTED is chosen, the approver is shown only the tool's name, not its arguments, and the approval endpoint's access control is not locked down. Consequential actions such as sending email, deleting files or posting tweets are irreversible.

C3 Tool & action scoping

Minimal 0.05 / 1.00

Tools pass model arguments straight through. File tools' path handling is not a strict boundary. The web scraper fetches any URL, including internal addresses. Pydantic schemas only check types. The default tool set offered in the GUI includes Write File.

C4 Code-execution isolation

Minimal 0.00 / 1.00

SuperAGI has no sandbox. Not every model-influenced execution path in task workflows is confined. The worker process holds every credential, runs as root in a container with no hardening, and has the application source mounted read-write from the host. Startup also runs downloaded tool code in-process.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

Search results, scraped pages, emails, GitHub PRs and files enter the model's context with no marking, and tool results are stored and replayed with the 'system' role, giving injected text the same standing as the operator's instructions. Nothing limits a hijacked agent: in the default God Mode it can read secrets and send them out through email, Slack, Twitter or a scraped URL, and take irreversible actions, all unattended.

C6 Memory, context & configuration integrity

Minimal 0.10 / 1.00

When the OpenAI model is used, every model reply and raw tool result is written unvalidated into a Redis vector index shared by all agents and organisations, and later read back into a system-role prompt by the thinking tool. Retrieval is filtered by execution id, so this store mostly affects the same run. A more durable path exists through the file tools.

C7 Third-party extensions

Minimal 0.00 / 1.00

Every time the backend or worker container starts, it downloads the latest main-branch zip of the TransformerOptimus/SuperAGI-Tools repository (and any user-added GitHub tool links), without pinning or integrity checks, pip-installs each tool's requirements as root, and imports the tool code into the server process. Any user can add a new GitHub tool link through the API. A compromise of that repository or any listed tool runs with all of SuperAGI's credentials.

C8 Secrets & sensitive-data protection

Minimal 0.00 / 1.00

Credentials live in a plaintext config.yaml, and default secrets and stored tool keys are not locked down. Nothing is redacted: tool outputs are logged at info level. Analytics are only enabled when the operator provides IDs.

C9 Audit & traceability

Minimal 0.38 / 1.00

Each step's raw model reply (which contains the tool name and arguments) and the tool's result are saved as timestamped rows in Postgres, and approval decisions are stored in their own table. There is no actor attribution beyond a single shared user, no tamper protection, and the worker process that executes model-controlled code holds the database credentials. Records are written after the tool runs, so a crash mid-call loses it.

C10 Limits & kill switch

Minimal 0.38 / 1.00

Each run has an iteration cap (25 by default in the GUI) enforced before every step, and runs older than one day are skipped. There is no token or cost cap: a Budget table exists but is never checked. Stopping a run only changes a status field that the next step checks, so an in-flight tool call finishes, and scheduled agents keep firing from the Celery beat scheduler.