BoundBench

Zed (Agent panel)

High-performance code editor with built-in agentic coding and ACP host

github.com/zed-industries/zed · 2026-10-03 · a846890

Defense-in-depth score

4.0 / 10

Minimal

Zed's built-in agent asks before every command, edit, fetch and MCP call by default, and runs terminal commands in a genuine OS sandbox with no network and writes confined to the project. The dominant risk is leakage rather than destruction: the chat view is not locked down against unattended data egress, and sandboxed commands still see your full environment and home directory. There are no step, time or spend limits on a turn.

Key gaps (2)

  1. Sandboxed terminal commands inherit the user's full shell environment and can read the whole filesystem (including ~/.ssh and cloud credential files); only writes and network are restricted. C4 · Code-execution isolation
  2. Every agent terminal command (sandboxed or not) and every MCP server inherits the user's full environment, so long-lived keys exported there are reachable by the model's commands. C8 · Secrets & sensitive-data protection

Criteria

C1 Identity & least privilege

Minimal 0.17 / 1.00

Zed's agent runs with your own account and does nothing to narrow it. Every terminal command the agent runs inherits your full shell environment (including any API keys or cloud tokens exported there), and MCP servers inherit it too. Zed's own model-provider keys stay in the OS keychain and are not handed to tools. What limits the damage is not a narrower identity but other layers: the default sandbox blocks network and out-of-project writes, and every terminal command needs your approval.

C2 Approval gates

Moderate 0.65 / 1.00

Approval is on by default: every built-in tool that changes files, runs commands, fetches URLs, searches the web or invokes a skill, and every MCP tool, asks you first. For terminal commands you see the exact command, and allow/deny rules are regular expressions checked against each parsed sub-command of chained shell commands, with command substitution refused unless everything is auto-allowed. File edits are approved by path before the new content is shown, but every agent edit can be reviewed and rejected afterwards and Zed takes git checkpoints you can restore. Auto-approval for everything is a single ordinary setting with no loud name, and nothing undoes MCP or network side effects.

C3 Tool & action scoping

Moderate 0.50 / 1.00

Zed's file tools are well scoped: paths are resolved against the project with symlink-escape checks, and files matching the private-files list (.env, keys, certificates) are refused by read and search. The fetch tool asks for each host, re-checks every redirect and refuses loopback, private and cloud-metadata addresses. But the default 'Write' profile also gives the agent a general shell, delete, and all MCP tools, and the shell accepts any command apart from command substitution; its reach is bounded only by the sandbox.

C4 Code-execution isolation

Moderate 0.53 / 1.00

Agent terminal commands run inside a real OS sandbox by default on macOS (Seatbelt), Linux (bubblewrap with user, PID, IPC and network namespaces plus a seccomp filter that blocks Unix sockets) and Windows via WSL. Writes are limited to the open project and a temporary directory, Git metadata is read-only, and network is off. Leaving the sandbox needs a stated reason and your approval, and if bubblewrap is missing Zed asks rather than silently running on the host. But the sandbox can read your whole home directory and receives your full environment, so credentials are visible to anything the agent runs; MCP servers, language servers and remote (SSH) projects run without it, and sandbox boundary handling for project configuration does not cover every path.

C5 Untrusted input blast radius

Minimal 0.45 / 1.00

Zed does not try to detect prompt injection, but its defaults blunt a hijack: every egress and state-changing tool (terminal, edits, fetch, web search, MCP) needs your approval whatever the agent has read, the terminal sandbox has no network, and read/search refuse .env and key files. The gap is the chat view itself, which is not locked down against unattended data egress. Tool results, files and MCP output all enter the conversation with no provenance marking.

C6 Memory, context & configuration integrity

Moderate 0.50 / 1.00

Zed has no long-term memory store, and settings that could add MCP servers or language servers from a repository's .zed/settings.json only load after you explicitly trust that folder; agent permissions and sandbox settings can only be set in your user settings. Project skills also wait for trust, and the agent's edits to .zed/, .agents/skills/ or your config directory always prompt. However, instruction files in the project root (.rules, AGENTS.md, CLAUDE.md and similar) are loaded into the system prompt silently even in untrusted folders, and the agent can rewrite them (after an approved edit or command) to steer future sessions.

C7 Third-party extensions

Minimal 0.30 / 1.00

No third-party MCP server is enabled by default; you add one in settings (or a trusted project's settings), and its tools still need approval. Nothing pins or verifies MCP server code, and changed tool definitions are not re-approved. Zed extensions come from Zed's registry and auto-update by default, and the default capability grant lets them run any process, download any file and install any npm package. MCP servers launch as ordinary processes with your full environment.

C8 Secrets & sensitive-data protection

Minimal 0.28 / 1.00

Zed keeps its own model-provider keys in the OS keychain, and the agent's read and search tools refuse files on the private-files list (.env, keys, certificates) by default. There is no redaction of tool output sent to the model, of logs, or of saved conversation history, and terminal commands and MCP servers inherit your full environment, so any key exported in your shell is within reach of a command the agent runs. Usage metrics and crash reports are on by default; agent telemetry events carry metadata (model, token counts), not prompts.

C9 Audit & traceability

Minimal 0.38 / 1.00

Each agent thread, including its tool calls, tool results and sub-agent threads (linked to their parent), is saved to a local database in Zed's data directory, outside the project the agent can write to. The record has no per-call timestamps and does not record your approvals or denials, saves are whole-thread snapshots whose failures are only logged, and there is no tamper evidence or export.

C10 Limits & kill switch

Minimal 0.25 / 1.00

There is no limit on how many steps, how long, or how many tokens an agent turn may use. MCP calls time out after 60 seconds by default, model retries are capped, and terminal commands only time out if the model asks for a timeout. Stopping works well: cancel stops the turn, cancels running sub-agents and kills running terminal commands.