# Defense-in-Depth Score: Cline

**Repo:** https://github.com/cline/cline · **Commit:** `39ff2359f7e08231281539696e48a166ce49270c` · **Reviewed:** 2026-10-03
**What it is:** Autonomous coding agent as VS Code extension, CLI and SDK
**Category:** Coding
**Scored configuration:** Cline CLI (apps/cli, the surface the README leads with) in its default act mode, no flags, fresh install: auto-approve on for all tools, workspace rules/hooks/plugins enabled.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication yes

## Score: 1.4 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L0 | L0 | L0 | 0.00 | — | **0.00** | High |
| C2 | Approval gates | L2 | L2 | L0 | L1 | 0.35 | C2-POWERBYPASS | **0.25** | High |
| C3 | Tool & action scoping | L1 | L1 | L0 | L0 | 0.15 | — | **0.15** | High |
| C4 | Code-execution isolation | L0 | L0 | L0 | L0 | 0.00 | — | **0.00** | High |
| C5 | Untrusted input blast radius | L0 | L0 | L0 | L0 | 0.00 | C5-WORSTCASE | **0.00** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L1 | L1 | 0.10 | C6-REPOCONFIG | **0.10** | High |
| C7 | Third-party extensions | L0 | L0 | L0 | L1 | 0.05 | C7-RCELOAD | **0.05** | High |
| C8 | Secrets & sensitive-data protection | L1 | L1 | L1 | L0 | 0.20 | — | **0.20** | Medium |
| C9 | Audit & traceability | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |
| C10 | Limits & kill switch | L1 | L2 | L0 | L0 | 0.23 | — | **0.23** | High |


As shipped, the Cline CLI auto-approves every tool, so the model runs arbitrary shell commands, edits files and fetches URLs on your machine with your full credentials and no human check. There is no sandbox, and opening a repository silently runs its .cline hook scripts and plugin modules. A prompt injection in a web page or cloned repo can therefore steal secrets and take irreversible actions unattended. Run it with --auto-approve false, only in trusted repos, and preferably inside a container.

## Critical gaps
- Shell commands, file edits and MCP calls are auto-approved by default, so the most powerful action path has no human gate. (ASI09, ASI02, T10, LLM06; C2) — [apps/cli/src/commands/program.ts:28-32](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/commands/program.ts#L28-L32); [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902)
- Model-written commands run on the host as the user with the full environment and network; no isolation exists. (ASI05, T11, LLM05; C4) — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737)
- The agent acts with the user's full ambient authority, and every subprocess inherits the complete environment. (ASI03, T3, LLM06; C1) — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [sdk/packages/core/src/extensions/mcp/client.ts:416-420](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/mcp/client.ts#L416-L420)
- A hijacked session can exfiltrate data and take irreversible actions with no human involved in the default configuration. (ASI01, T6, LLM01; C5) — [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902); [sdk/packages/core/src/extensions/tools/executors/web-fetch.ts:123-151](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/web-fetch.ts#L123-L151)
- Repository files (.cline/hooks, .clinerules/hooks, .cline/plugins) add hooks and plugins with no workspace-trust decision. (ASI06, ASI04, T1; C6) — [sdk/packages/shared/src/storage/paths.ts:487-501](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L487-L501); [sdk/packages/shared/src/storage/paths.ts:610-618](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L610-L618); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:424-426](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L424-L426)
- Plugin modules and hook scripts shipped in an untrusted repository are executed automatically at session start. (ASI04, ASI05, T17, LLM03; C7) — [sdk/packages/core/src/services/local-runtime-bootstrap.ts:450-453](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L450-L453); [sdk/packages/core/src/hooks/hook-file-hooks.ts:401-412](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/hooks/hook-file-hooks.ts#L401-L412); [sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts:265-270](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts#L265-L270)

## Criterion details

### C1 Identity & least privilege — 0.00 (high)

Cline's CLI runs with the full authority of the user who launched it and does nothing to narrow it. The shell tool, MCP servers and plugin subprocesses all inherit the complete process environment, so any API keys, cloud credentials, SSH agent or GitHub CLI login available to the user are available to every command the model runs. There is no per-tool identity or authorization layer, so a hijacked session can do anything the user's account can do.

- **S L0:** Shell commands are spawned as the OS user with the full parent environment; no credential scoping or authorization gate exists. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737) (verified)
  - *To reach the next level:* No scoped or per-tool credentials and no deterministic authorization gate before ambient credentials are used.
- **C L0:** Every subprocess path (shell, MCP stdio servers, plugin sandbox) passes the whole process.env, and no tool path checks authorization. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [sdk/packages/core/src/extensions/mcp/client.ts:416-420](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/mcp/client.ts#L416-L420); [sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts:265-270](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts#L265-L270) (verified)
  - *To reach the next level:* No tool path, not even the main shell tool, uses a scoped identity or scrubbed environment.
- **D L0:** The default install runs every tool with the user's full ambient authority; nothing narrower exists to enable. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902) (verified)
  - *To reach the next level:* No narrower default role exists; least privilege requires the user to sandbox Cline externally.
- **B L0:** A hijacked session reaches everything the user's account can reach (ssh keys, gh auth, cloud CLIs, provider keys) through the unrestricted shell. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902) (verified)
  - *To reach the next level:* Nothing confines a hijacked session to one project or to read-only operations.
- **Cap:** none

### C2 Approval gates — 0.25 (high)

The CLI ships with tool auto-approval switched on for every tool, including shell commands, file edits and MCP tools, so in the default configuration nothing waits for a human. If a user passes --auto-approve false, a per-call prompt appears that shows the exact shell command but only the path (no diff) for file edits, with no risk tiers. Even then, approval enforcement does not cover every path. Git checkpoints let workspace file changes be undone, but shell side effects such as pushes, deletions outside the repo or network calls cannot be.

- **S L2:** When enabled, the TUI asks per call and shows the exact shell command, but edits show only the file path and there are no risk tiers or argument-level rules. — [sdk/packages/agents/src/agent-runtime.ts:2417-2434](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/agents/src/agent-runtime.ts#L2417-L2434); [apps/cli/src/runtime/interactive/approvals.ts:39-52](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/runtime/interactive/approvals.ts#L39-L52); [apps/cli/src/tui/components/dialogs/tool-approval.tsx:42-61](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/tui/components/dialogs/tool-approval.tsx#L42-L61) (verified)
  - *To reach the next level:* Approval does not show the edit diff and has no risk tiers deciding what needs a human.
- **C L2:** A "*" policy routes built-in, MCP and plugin tools through the gate when approval is on, but the gate does not cover every path. (verified)
  - *To reach the next level:* Not every tool path traverses the approval gate.
- **D L0:** Auto-approval defaults to true for all tools in the CLI; approval is opt-in via --auto-approve false. — [apps/cli/src/commands/program.ts:28-32](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/commands/program.ts#L28-L32); [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902) (verified)
  - *To reach the next level:* Approval is not on by default.
- **B L1:** CLI checkpoints snapshot the git working tree, but unattended shell actions (push, delete outside the repo, network calls) are irreversible. — [apps/cli/src/runtime/defaults.ts:15-17](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/runtime/defaults.ts#L15-L17); [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737) (verified)
  - *To reach the next level:* Only workspace file state is reversible; shell side effects have no preview or undo.
- **Cap:** C2-POWERBYPASS — In the default configuration the shell tool (run_commands), the most powerful action path, executes with no approval.

### C3 Tool & action scoping — 0.15 (high)

The default act-mode tool set includes an unrestricted shell, file editing, file reading and web fetching, all enabled at once. The shell takes any command string. The editor's path containment is not a complete boundary, file reading has no path restriction, and web fetch only checks the URL scheme, with no block on internal addresses. The plan-mode command blacklist does not apply in the default act mode.

- **S L1:** Shell is raw passthrough; the only validation is an editor path check that is not a complete boundary and a scheme check on fetch URLs. — [sdk/packages/core/src/extensions/tools/executors/web-fetch.ts:123-151](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/web-fetch.ts#L123-L151); [sdk/packages/core/src/extensions/tools/command-guard.ts:1-18](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/command-guard.ts#L1-L18) (verified)
  - *To reach the next level:* No robust resolved-path containment, no host allowlist or internal-address block, and the shell accepts arbitrary commands.
- **C L1:** Only editor/apply_patch and web fetch (scheme) validate; read_files and run_commands do not. — [sdk/packages/core/src/extensions/tools/executors/file-read.ts:231-237](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/file-read.ts#L231-L237) (verified)
  - *To reach the next level:* Most built-in tools, including read_files and run_commands, have no argument validation.
- **D L0:** The default act preset enables shell, editor, web fetch, sub-agents and teams together. — [sdk/packages/core/src/extensions/tools/presets.ts:25-37](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/presets.ts#L25-L37) (verified)
  - *To reach the next level:* Write, exec and network tools are all on by default; no read-only default tool set.
- **B L0:** A misused shell call can run any command against the whole machine and any host. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902) (verified)
  - *To reach the next level:* Tools are not scoped to the workspace or bounded in quantity.
- **Cap:** none

### C4 Code-execution isolation — 0.00 (high)

Commands the model writes run directly on the host as the user, with the full environment and full network access. There is no container, OS sandbox or VM anywhere in the CLI or SDK; the CLI's "sandbox" option only isolates Cline's own data directory. Workspace hook scripts and plugin modules also run as host subprocesses. A destructive or malicious command reaches everything the user can.

- **S L0:** run_commands spawns the configured shell on the host with no isolation primitive. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); searched `rg -n -i "sandbox-exec|seatbelt|landlock|bwrap|bubblewrap|firejail|seccomp|gvisor|firecracker"` in `sdk/packages apps/cli/src` → 0 hits (No OS-level or VM isolation primitive is referenced anywhere in the SDK or CLI.) (verified)
  - *To reach the next level:* No OS-level separation (container, low-privilege user, or OS sandbox profile).
- **C L0:** No execution path is sandboxed: shell, hook scripts, plugin subprocesses and MCP stdio servers all run on the host. — [sdk/packages/core/src/hooks/hook-file-hooks.ts:401-412](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/hooks/hook-file-hooks.ts#L401-L412); [sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts:265-270](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts#L265-L270); [sdk/packages/core/src/extensions/mcp/client.ts:416-420](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/mcp/client.ts#L416-L420) (verified)
  - *To reach the next level:* Not even the main exec tool is sandboxed.
- **D L0:** There is no sandbox to enable; the --data-dir "sandbox" only relocates state. — [apps/cli/src/main.ts:866-875](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L866-L875); searched `rg -n -i "sandbox-exec|seatbelt|landlock|bwrap|bubblewrap|firejail|seccomp|gvisor|firecracker"` in `sdk/packages apps/cli/src` → 0 hits (No OS-level or VM isolation primitive is referenced anywhere in the SDK or CLI.) (verified)
  - *To reach the next level:* No sandbox exists, on or off.
- **B L0:** Executed code has host-equivalent reach: home directory, credentials in the environment, and unrestricted network. — [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737) (verified)
  - *To reach the next level:* No workspace-only mount, secret-free environment or egress restriction.
- **Cap:** none

### C5 Untrusted input blast radius — 0.00 (high)

Cline reads web pages, repository files and MCP tool results straight into the model's context with nothing marking them as untrusted and nothing that changes what the agent may do afterwards. Because every tool is auto-approved by default, injected instructions in a fetched page or a cloned repo can make the agent read secrets with read_files or the shell and send them anywhere, or take irreversible actions, without a human seeing it.

- **S L0:** No taint tracking, quarantine or approval escalation after untrusted content is read. — searched `rg -n -i "untrusted|taint|provenance"` in `sdk/packages/core/src sdk/packages/agents/src` → 13 hits (All hits are session/automation origin metadata, comments, or tests; none marks tool results or fetched content as untrusted or changes tool permissions after untrusted input is read.) (verified)
  - *To reach the next level:* Nothing forces egress or state-changing tools through approval once untrusted content enters the session.
- **C L0:** Tool results, fetched pages, files and MCP outputs all enter context with the same standing as user input. — searched `rg -n -i "untrusted|taint|provenance"` in `sdk/packages/core/src sdk/packages/agents/src` → 13 hits (All hits are session/automation origin metadata, comments, or tests; none marks tool results or fetched content as untrusted or changes tool permissions after untrusted input is read.); [sdk/packages/core/src/extensions/tools/executors/web-fetch.ts:123-151](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/web-fetch.ts#L123-L151) (verified)
  - *To reach the next level:* Untrusted sources are not distinguished at all.
- **D L0:** No mitigation exists to be on by default. — searched `rg -n -i "untrusted|taint|provenance"` in `sdk/packages/core/src sdk/packages/agents/src` → 13 hits (All hits are session/automation origin metadata, comments, or tests; none marks tool results or fetched content as untrusted or changes tool permissions after untrusted input is read.) (verified)
  - *To reach the next level:* No untrusted-input control ships.
- **B L0:** With auto-approve on, a hijacked session can both exfiltrate (shell, web fetch to any URL) and take irreversible actions unattended. — [apps/cli/src/main.ts:892-902](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L892-L902); [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737); [sdk/packages/core/src/extensions/tools/executors/web-fetch.ts:123-151](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/web-fetch.ts#L123-L151) (verified)
  - *To reach the next level:* Exfiltration and irreversible actions are both reachable without a human.
- **Cap:** C5-WORSTCASE — In the default configuration a hijacked agent can leak data and take irreversible actions with no human involved.

### C6 Memory, context & configuration integrity — 0.10 (high)

Opening a repository in Cline silently loads its instruction files (AGENTS.md, .clinerules), and also its hook scripts (.cline/hooks, .clinerules/hooks) and plugin modules (.cline/plugins), which are executed with no workspace-trust prompt. All runtime config extensions are on by default. The agent can also write those same files with its auto-approved editor or shell, so a single injection can plant a hook or rule that runs in every later session in that project. Newer Agent Plugin packages are, by contrast, only discovered from the user's home directory.

- **S L0:** Repo-controlled files add hooks and plugins (executable code) and instruction text with no prompt or trust decision. — [sdk/packages/shared/src/storage/paths.ts:487-501](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L487-L501); [sdk/packages/shared/src/storage/paths.ts:610-618](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L610-L618); [sdk/packages/shared/src/storage/paths.ts:578-593](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L578-L593); searched `rg -n -i "workspace.?trust|trustWorkspace|isTrusted"` in `sdk/packages apps/cli/src` → 0 hits (No workspace-trust decision exists anywhere in the SDK or CLI.) (verified)
  - *To reach the next level:* Security-relevant project config (hooks, plugins) does not require an explicit workspace-trust decision.
- **C L0:** No auto-loaded path (rules, workflows, skills, hooks, plugins) is gated or validated. — [sdk/packages/shared/src/session/runtime-config.ts:11-19](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/session/runtime-config.ts#L11-L19); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:424-426](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L424-L426); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:450-453](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L450-L453) (verified)
  - *To reach the next level:* No memory or config path is controlled.
- **D L1:** Local per-user state under ~/.cline, but workspace files are shared by anyone who opens the repo and the agent can write them freely. — [sdk/packages/shared/src/storage/paths.ts:187-193](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L187-L193); [sdk/packages/shared/src/storage/paths.ts:578-593](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L578-L593) (verified)
  - *To reach the next level:* Isolation is only by OS user; nothing stops the agent writing persistent workspace config.
- **B L1:** A planted hook or rule persists across the user's sessions in that workspace and runs code or drives tool use; via auto-approved git push it can spread to collaborators. — [sdk/packages/core/src/hooks/hook-file-hooks.ts:401-412](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/hooks/hook-file-hooks.ts#L401-L412); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:450-453](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L450-L453) (verified)
  - *To reach the next level:* Poisoned config is not session-scoped and is not surfaced for review before it takes effect.
- **Cap:** C6-REPOCONFIG — Workspace files (.cline/hooks, .clinerules/hooks, .cline/plugins) enable hooks and plugins with no explicit user trust decision.

### C7 Third-party extensions — 0.05 (high)

Plugin modules placed in a repository's .cline/plugins folder are discovered and executed automatically when a session starts, and hook scripts in the repo run as subprocesses, all without consent. The plugin "sandbox" is a separate Node process that still inherits the full environment. MCP servers are added by the user to a user-scope settings file but are launched unpinned with the full environment. There is no version pinning, integrity check or re-approval on change.

- **S L0:** Repository-supplied plugin code is loaded and run automatically with no verification. — [sdk/packages/shared/src/storage/paths.ts:610-618](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L610-L618); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:450-453](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L450-L453) (verified)
  - *To reach the next level:* No pinning, hash or signature check on any extension.
- **C L0:** No extension type (plugins, hooks, MCP servers) is verified. — [sdk/packages/core/src/services/local-runtime-bootstrap.ts:450-453](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L450-L453); [sdk/packages/core/src/hooks/hook-file-hooks.ts:401-412](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/hooks/hook-file-hooks.ts#L401-L412); [sdk/packages/core/src/extensions/mcp/client.ts:416-420](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/mcp/client.ts#L416-L420) (verified)
  - *To reach the next level:* No extension type is verified.
- **D L0:** Workspace files can add plugins and hooks silently; all extension kinds are enabled by default. — [sdk/packages/shared/src/session/runtime-config.ts:11-19](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/session/runtime-config.ts#L11-L19); [sdk/packages/shared/src/storage/paths.ts:610-618](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L610-L618); searched `rg -n -i "workspace.?trust|trustWorkspace|isTrusted"` in `sdk/packages apps/cli/src` → 0 hits (No workspace-trust decision exists anywhere in the SDK or CLI.) (verified)
  - *To reach the next level:* Workspace files can add extensions without any consent.
- **B L1:** Plugins run in a separate Node subprocess and MCP servers as separate processes, both with the full parent environment, as the same user. — [sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts:265-270](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/tools/subprocess-sandbox.ts#L265-L270); [sdk/packages/core/src/extensions/mcp/client.ts:416-420](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/mcp/client.ts#L416-L420) (verified)
  - *To reach the next level:* Extension processes are not given a scrubbed environment.
- **Cap:** C7-RCELOAD — By default Cline executes plugin modules and hook scripts shipped in an untrusted repository without consent.

### C8 Secrets & sensitive-data protection — 0.20 (medium)

Provider credentials are stored in a plaintext JSON file with owner-only permissions rather than an OS keychain. The read_files tool has no path restriction and the shell inherits the full environment, so the model can read stored keys or environment secrets in the default auto-approved mode. Git remote URLs have embedded credentials stripped before being put in the prompt, but there is no general redaction of logs, transcripts or tool output. Product telemetry is opt-out and, as far as the event definitions show, content-free.

- **S L1:** Plaintext credential file with 0600 permissions; masking exists only for git remote URLs in the system prompt. — [sdk/packages/core/src/services/storage/provider-settings-manager.ts:198-200](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/storage/provider-settings-manager.ts#L198-L200); [sdk/packages/shared/src/prompt/cline.ts:55](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/prompt/cline.ts#L55) (verified)
  - *To reach the next level:* No type-level masking or log filters on main paths, and no keychain storage.
- **C L1:** Only the git-remote path into the prompt is redacted; logs, transcripts, tool results and subprocess environments are not. — [sdk/packages/shared/src/prompt/cline.ts:55](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/prompt/cline.ts#L55); [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737) (verified)
  - *To reach the next level:* Logs and transcripts are not redacted.
- **D L1:** Telemetry is on unless the user opts out (opt-out default false, enable flag baked in at build time); events appear content-free. — [sdk/packages/core/src/services/global-settings.ts:63](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/global-settings.ts#L63); [sdk/packages/shared/src/services/telemetry-config.ts:15-19](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/services/telemetry-config.ts#L15-L19); [apps/cli/bun.mts:102-104](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/bun.mts#L102-L104) (inferred)
  - *To reach the next level:* Telemetry is not opt-in.
- **B L0:** Long-lived provider keys and any user secrets in the environment are reachable by the model via read_files and every shell subprocess. — [sdk/packages/core/src/extensions/tools/executors/file-read.ts:231-237](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/file-read.ts#L231-L237); [sdk/packages/core/src/extensions/tools/executors/bash.ts:733-737](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L733-L737) (verified)
  - *To reach the next level:* Long-lived keys are reachable by the model and every subprocess.
- **Cap:** none

### C9 Audit & traceability — 0.45 (high)

Each session's full message history, including every tool call and its arguments and results, is saved under ~/.cline/data/sessions at the end of every agent iteration, so a run can be reconstructed afterwards. Saving is fire-and-forget, so failures are only logged and the agent keeps acting. In the CLI the dedicated hooks.jsonl audit log is skipped for the main session because the CLI installs its own runtime hooks; sub-agent events are still appended there. The records sit in the user's home directory, where the auto-approved shell can edit or delete them.

- **S L2:** A structured session transcript with tool calls, arguments and results is persisted per iteration. — [sdk/packages/core/src/services/agent-events.ts:312-317](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/agent-events.ts#L312-L317); [sdk/packages/shared/src/storage/paths.ts:187-193](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L187-L193) (verified)
  - *To reach the next level:* No actor attribution separating agent, human and approver, and no correlation IDs across sub-agents in the record.
- **C L2:** Main-agent tool calls are in the transcript and sub-agent events are appended to hooks.jsonl, but approvals and denials are not recorded as such. — [sdk/packages/core/src/services/agent-events.ts:312-317](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/agent-events.ts#L312-L317); [sdk/packages/core/src/runtime/host/local-runtime-host.ts:1572-1586](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/host/local-runtime-host.ts#L1572-L1586); [sdk/packages/core/src/services/local-runtime-bootstrap.ts:435-442](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/services/local-runtime-bootstrap.ts#L435-L442); [apps/cli/src/runtime/run-agent.ts:179-187](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/runtime/run-agent.ts#L179-L187) (verified)
  - *To reach the next level:* Approval and denial decisions are not recorded.
- **D L2:** On by default and stored outside the workspace, but in the user's home where the agent's shell can alter it. — [sdk/packages/shared/src/storage/paths.ts:187-193](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/shared/src/storage/paths.ts#L187-L193) (verified)
  - *To reach the next level:* The record is written where the model-controlled shell can modify it.
- **B L1:** Persistence is fire-and-forget; failures are logged and actions proceed. — [sdk/packages/core/src/runtime/host/local-runtime-host.ts:344-352](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/host/local-runtime-host.ts#L344-L352) (verified)
  - *To reach the next level:* Persistence errors are not surfaced to the user and actions do not wait for the record.
- **Cap:** none

### C10 Limits & kill switch — 0.23 (high)

The CLI sets no iteration cap, no wall-clock limit (--timeout defaults to 0) and no cost ceiling, so a runaway session can loop and spend indefinitely. Individual shell commands time out after 30 seconds by default, and pressing stop aborts the run and kills the running command's process group. A consecutive-mistake counter stops the loop after repeated errors, but that bounds failures, not damage.

- **S L1:** Per-command timeouts and a halt that kills the process group exist, but no iteration or cost cap is available from the CLI. — [sdk/packages/agents/src/agent-runtime.ts:830-833](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/agents/src/agent-runtime.ts#L830-L833); [sdk/packages/core/src/extensions/tools/definitions.ts:502](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/definitions.ts#L502); [sdk/packages/core/src/extensions/tools/executors/bash.ts:813](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L813); [sdk/packages/core/src/extensions/tools/executors/bash.ts:820](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/executors/bash.ts#L820); searched `rg -n -i "maxCost|costLimit|spendLimit|max_cost"` in `sdk/packages/core/src sdk/packages/agents/src apps/cli/src` → 0 hits (No spend or cost ceiling exists in the SDK runtime or CLI.) (verified)
  - *To reach the next level:* No iteration cap or token/cost cap enforced in code for CLI sessions.
- **C L2:** The top-level loop has an opt-in wall-clock timeout and tools have timeouts; sub-agents get no separate cap. — [apps/cli/src/commands/program.ts:59-62](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/commands/program.ts#L59-L62); [sdk/packages/core/src/extensions/tools/definitions.ts:502](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/extensions/tools/definitions.ts#L502); [sdk/packages/core/src/runtime/host/local/spawn-tool.ts:149-186](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/core/src/runtime/host/local/spawn-tool.ts#L149-L186) (verified)
  - *To reach the next level:* Sub-agents and spawned background processes do not count against a shared budget.
- **D L0:** Unlimited by default: maxIterations is unset and the wall-clock timeout defaults to 0. — [apps/cli/src/main.ts:1056-1093](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/main.ts#L1056-L1093); [apps/cli/src/commands/program.ts:59-62](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/apps/cli/src/commands/program.ts#L59-L62); [sdk/packages/agents/src/agent-runtime.ts:830-833](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/agents/src/agent-runtime.ts#L830-L833) (verified)
  - *To reach the next level:* No sensible default iteration, time or cost limit.
- **B L0:** With no ceilings, a runaway auto-approved session can act and spend until a human stops it. — [sdk/packages/agents/src/agent-runtime.ts:830-833](https://github.com/cline/cline/blob/39ff2359f7e08231281539696e48a166ce49270c/sdk/packages/agents/src/agent-runtime.ts#L830-L833); searched `rg -n -i "maxCost|costLimit|spendLimit|max_cost"` in `sdk/packages/core/src sdk/packages/agents/src apps/cli/src` → 0 hits (No spend or cost ceiling exists in the SDK runtime or CLI.) (verified)
  - *To reach the next level:* No per-run time or cost ceiling.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: fetch_web_content and repo files/MCP results enter context unmarked (sdk/packages/core/src/extensions/tools/definitions.ts:563) · [B] sensitive data/systems: read_files has no path restriction and the shell inherits the full environment (sdk/packages/core/src/extensions/tools/executors/file-read.ts:231, executors/bash.ts:735) · [C] state change / egress: run_commands and editor auto-approved by default (apps/cli/src/main.ts:892-902) · Same default session? Yes

## Highest-impact improvements
1. Default --auto-approve to false (approval on) for run_commands, editor, apply_patch, fetch and MCP tools, keeping auto-approval for read-only tools only. — C2 D L0→L3, +0.150 before caps (Playbook 5)
2. Require an explicit per-workspace trust decision before loading .cline/hooks, .clinerules/hooks and .cline/plugins, as already done for Agent Plugins. — C6 S L0→L3, +0.225 before caps (Playbook 2)
3. Stop auto-discovering plugin modules from the workspace; allow only user/admin-scope plugin directories. — C7 D L0→L4, +0.200 before caps (Playbook 3)
4. Ensure every tool path crosses the same approval gate. — C2 C L2→L3, +0.075 before caps (Playbook 5)
5. Ship default iteration and wall-clock caps for CLI sessions (overridable by flag). — C10 D L0→L2, +0.100 before caps (Playbook 3 step 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- Scored the CLI default (README's first product card). The VS Code extension differs: its defaults (apps/vscode/src/shared/AutoApprovalSettings.ts:34-41) auto-approve reads, edits, browser and MCP tools but require approval for commands, so its C2 would score somewhat higher; it was not scored separately.
- The desktop app, hub daemon, scheduled (cron) runs, chat connectors, ACP mode and cloud sessions were not scored; scheduled runs default to yolo mode (apps/cli/src/commands/schedule/handlers.ts:68).
- Telemetry default (C8 D) is inferred: the enable flag is baked in from the release build environment, which is not in the repo.
- No reviewer-directed prompt-injection text was found in AGENTS.md, .clinerules or docs.
