# Defense-in-depth score: Vibe Kanban

**Repo:** https://github.com/BloopAI/vibe-kanban · **Commit:** `d5cbb5380fa0b32e98ef9b8d987f63decce4be3a` (v0.1.45-20260919085201) · **Reviewed:** 2026-10-05
**What it is:** Local kanban web app that plans tasks and runs coding-agent CLIs (Claude Code, Codex, Gemini CLI, Amp, Cursor, Copilot and others) in per-task git worktrees, with diff review and PR creation.
**Category:** Coding
**Scored configuration:** Local app launched with `npx vibe-kanban`, fresh install, default Claude Code agent with its shipped DEFAULT profile, telemetry and relay settings at their defaults.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication yes

## Score: 1.2 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L0 | L0 | L0 | 0.00 | none | **0.00** | High |
| C2 | Approval gates | L3 | L2 | L1 | L2 | 0.53 | C2-SELFAPPROVE | **0.25** (alt) | High |
| C3 | Tool & action scoping | L0 | L0 | L0 | L0 | 0.00 | none | **0.00** | High |
| C4 | Code-execution isolation | L0 | L0 | L0 | L0 | 0.00 | none | **0.00** | High |
| C5 | Untrusted input blast radius | L0 | L0 | L0 | L0 | 0.00 | C5-WORSTCASE | **0.00** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L1 | L1 | 0.10 | C6-REPOCONFIG | **0.10** | High |
| C7 | Third-party extensions | L1 | L1 | L1 | L0 | 0.20 | none | **0.20** | High |
| C8 | Secrets & sensitive-data protection | L1 | L1 | L1 | L0 | 0.20 | none | **0.20** | High |
| C9 | Audit & traceability | L2 | L2 | L2 | L1 | 0.45 | none | **0.45** | High |
| C10 | Limits & kill switch | L0 | L0 | L0 | L0 | 0.00 | none | **0.00** | High |


Vibe Kanban launches every coding agent with its permission prompts switched off by default (Claude Code with --dangerously-skip-permissions, Codex with full access, Gemini and Qwen in yolo mode) and runs it unsandboxed on the host with the user's full environment. A prompt injection in a repository, issue or web page can make an agent read credentials, push code and send data out with no human involved. Each task gets its own git worktree and branch, which keeps file changes reviewable, and a per-call approval mode exists, but it is opt-in, covers only some agents, and is not tamper-resistant.

## Critical gaps
- Agents run with the user's full inherited environment and CLI logins and no scoped identity, so a hijacked agent holds the user's whole account. (ASI03, T3; C1). Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642)
- Every shipped agent profile disables the agent's permission prompts, so shell commands run with no approval by default. (ASI02, ASI09, T10; C2). Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/executors/src/executors/claude.rs:176-178](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L176-L178); [crates/executors/default_profiles.json:27](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L27)
- The opt-in approval mode does not protect its own configuration from the agent, so the model can widen its permissions without a human. (ASI09, T15; C2). Evidence: [crates/executors/src/executors/claude.rs:236-245](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L236-L245); [crates/executors/src/executors/claude.rs:199-207](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L199-L207)
- Agents and scripts run on the host as the user with no sandbox and the full credential-bearing environment. (ASI05, T11; C4). Evidence: [crates/executors/src/executors/claude.rs:650](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L650); [crates/executors/src/actions/script.rs:55-69](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/actions/script.rs#L55-L69); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.)
- In the default configuration a prompt-injected agent can exfiltrate secrets and take irreversible actions with no human in the loop. (ASI01, LLM01, T6; C5). Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367)
- Repository-controlled instruction and settings files load into agents launched with prompts disabled, with no workspace-trust decision. (ASI06, T1; C6). Evidence: [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016); [crates/db/src/models/session.rs:186-187](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/db/src/models/session.rs#L186-L187); [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6)
- Agent CLIs and MCP servers are fetched through npx (some at @latest) and run as the user with the full environment. (ASI04, T17; C7). Evidence: [crates/executors/src/executors/amp.rs:37](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/amp.rs#L37); [crates/executors/default_mcp.json:3-7](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_mcp.json#L3-L7); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642)

## Criterion details

### C1 Identity & least privilege: 0.00 (high confidence)

Every coding agent runs as the desktop user with the server's full inherited environment, plus the user's own CLI logins (Claude, gh, az, SSH), and Vibe Kanban adds no scoped identity or authorization layer between the agent and those credentials. Pull requests are created with the user's gh or az CLI login. A hijacked agent therefore holds everything the user can reach.

- **S L0:** Agents inherit the server's whole environment and the user's ambient CLI credentials; nothing narrows them. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642); searched `rg -n 'env_clear'` in `crates` → 0 hits (No agent or script subprocess has its inherited environment cleared; only the variables listed in ExecutionEnv are added on top.) (verified)
  - *To reach the next level:* No dedicated or scoped identity; credentials are not narrowed per role or tool.
- **C L0:** No authorization layer sits between agent tools and ambient credentials; scripts and agents get the same environment. Evidence: [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642); [crates/executors/src/actions/script.rs:55-69](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/actions/script.rs#L55-L69); searched `rg -n 'env_clear'` in `crates` → 0 hits (No agent or script subprocess has its inherited environment cleared; only the variables listed in ExecutionEnv are added on top.) (verified)
  - *To reach the next level:* No tool path is checked against an authorization layer.
- **D L0:** The default install runs agents with the user's full privilege and permission prompts disabled. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/services/src/services/config/versions/v8.rs:137](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/config/versions/v8.rs#L137) (verified)
  - *To reach the next level:* Default runs with the user's full privilege; no narrower default.
- **B L0:** A hijacked agent reaches the user's whole account: home directory, git and SSH credentials, cloud CLIs and API keys in the environment. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642) (verified)
  - *To reach the next level:* Blast radius is the user's full account across services.
- **Cap:** none

### C2 Approval gates: 0.25 (high confidence)

Every shipped agent profile turns the agent's own permission prompts off by default: Claude Code gets --dangerously-skip-permissions, Codex runs with full access, and Gemini and Qwen run in yolo mode. The docs describe this setting as removing safety guardrails. An opt-in 'Ask' mode routes each non-read tool call to an approval card in the UI that shows the call and denies on timeout. It covers only five of the nine agents (the others auto-approve), and a request without a tool ID is allowed through, as a source comment notes. The approval configuration is not tamper-resistant against the agent. Each task runs on its own branch in a separate git worktree, so file changes can be reviewed before merging, but shell side effects, pushes and external calls cannot be undone.

- **default configuration** (default; raw 0.10, cap C2-POWERBYPASS → 0.10)
  - **S L0:** In the default configuration there is no approval: the default profile passes --dangerously-skip-permissions and the session runs in bypass mode. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/executors/src/executors/claude.rs:176-178](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L176-L178); [crates/executors/src/executors/claude.rs:199-207](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L199-L207) (verified)
    - *To reach the next level:* No per-call approval in the shipped default.
  - **C L0:** Shell, file writes, network and MCP tools all run ungated by default. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/executors/default_profiles.json:27](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L27); [crates/executors/default_profiles.json:20](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L20) (verified)
    - *To reach the next level:* The most powerful tool (shell) is exempt by default.
  - **D L0:** Approval is opt-in; every agent's DEFAULT profile disables prompts, and the docs say this removes guardrails. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/services/src/services/config/versions/v8.rs:137](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/config/versions/v8.rs#L137); [docs/settings/agent-configurations.mdx:34](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/docs/settings/agent-configurations.mdx#L34) (verified)
    - *To reach the next level:* Approval is opt-in.
  - **B L2:** Agent work lands on a separate branch in its own worktree and is reviewed as a diff before merge; shell side effects, pushes and external actions have no undo. Evidence: [crates/worktree-manager/src/worktree_manager.rs:510-522](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/worktree-manager/src/worktree_manager.rs#L510-L522); [crates/git-host/src/github/cli.rs:243](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/git-host/src/github/cli.rs#L243) (verified)
    - *To reach the next level:* No checkpoints or previews for non-file actions such as pushes and external calls.
- **opt-in 'Ask' approval mode (approvals: true)** (alt; raw 0.53, cap C2-SELFAPPROVE → 0.25) ← counted
  - **S L3:** Each non-read tool call is held for an approval card that shows the tool and its normalized call; the approved input is passed through unchanged and a timeout denies. Evidence: [crates/executors/src/executors/claude.rs:236-245](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L236-L245); [crates/executors/src/executors/claude/client.rs:121-126](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude/client.rs#L121-L126); [crates/executors/src/executors/claude/client.rs:134-137](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude/client.rs#L134-L137); [packages/web-core/src/features/workspace-chat/ui/DisplayConversationEntry.tsx:266-281](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/packages/web-core/src/features/workspace-chat/ui/DisplayConversationEntry.tsx#L266-L281) (verified)
    - *To reach the next level:* No argument-level allow/deny policy on parsed arguments.
  - **C L2:** The hook covers every Claude tool except a read-only list, but only five executors use the approval bridge (the rest auto-approve), and a call without a tool ID is allowed. Evidence: [crates/executors/src/executors/claude.rs:236-245](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L236-L245); [crates/local-deployment/src/container.rs:1331-1346](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1331-L1346); [crates/executors/src/approvals.rs:76-82](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/approvals.rs#L76-L82); [crates/executors/src/executors/claude/client.rs:310-320](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude/client.rs#L310-L320) (verified)
    - *To reach the next level:* Four executors and calls without a tool ID bypass the gate.
  - **D L1:** The mode is chosen per session in the UI and is not protected from changes made from the agent's environment. Evidence: [crates/executors/src/executors/claude.rs:199-207](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L199-L207); [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6) (verified)
    - *To reach the next level:* The approval configuration is not tamper-resistant against the agent.
  - **B L2:** Same as default: file changes are isolated to a reviewable worktree branch; other actions are not reversible. Evidence: [crates/worktree-manager/src/worktree_manager.rs:510-522](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/worktree-manager/src/worktree_manager.rs#L510-L522) (verified)
    - *To reach the next level:* No checkpoints or previews for non-file actions.
- **Cap:** C2-SELFAPPROVE: Even in approval mode the model can widen its own permissions without a human, because protection of the approval configuration is not tamper-resistant.
- **Notes:** Plan mode auto-approves every tool except plan exit and questions.

### C3 Tool & action scoping: 0.00 (high confidence)

The consequential tools are the agent runtimes' own general-purpose ones (shell, file write, web fetch), passed through with no extra argument validation by Vibe Kanban, and the default profiles switch off the runtimes' own restrictions (for example Codex's workspace-write sandbox). The agent starts in a per-task git worktree, but nothing stops it from reaching outside it. Vibe Kanban's own MCP tools are typed but opt-in. A misused tool can reach the whole machine.

- **S L0:** Shell commands, paths and URLs from the model reach the runtime's tools unvalidated, and the runtimes' own restrictions are disabled by default. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/executors/default_profiles.json:27](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L27); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.) (verified)
  - *To reach the next level:* No allowlist validation of commands, paths or URLs.
- **C L0:** No agent tool path is validated by Vibe Kanban. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.) (verified)
  - *To reach the next level:* No tool validates inputs.
- **D L0:** Write, exec and network tools are all enabled by default. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/executors/default_profiles.json:20](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L20) (verified)
  - *To reach the next level:* Everything is enabled by default; no read-only default.
- **B L0:** A misused shell tool runs any command against the whole machine as the user. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:650](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L650) (verified)
  - *To reach the next level:* General-purpose tools reach the whole machine.
- **Cap:** none

### C4 Code-execution isolation: 0.00 (high confidence)

Agents, and the setup, cleanup and dev-server scripts, run as ordinary processes of the desktop user on the host, with the full inherited environment. Vibe Kanban ships no container or OS sandbox, and its default Codex profile turns off Codex's own sandbox. Per-task git worktrees separate the files but are not an isolation boundary. Model-written commands can reach the user's whole home directory, credentials and network.

- **S L0:** Same-user host subprocesses; no isolation primitive. Evidence: [crates/executors/src/executors/claude.rs:650](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L650); [crates/executors/src/actions/script.rs:55-69](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/actions/script.rs#L55-L69); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.) (verified)
  - *To reach the next level:* No OS-level separation (container, dedicated user, sandbox profile).
- **C L0:** No execution path is sandboxed. Evidence: [crates/executors/src/actions/script.rs:55-69](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/actions/script.rs#L55-L69); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.) (verified)
  - *To reach the next level:* The main exec path is not sandboxed.
- **D L0:** No sandbox is on by default; the Codex default profile selects danger-full-access. Evidence: [crates/executors/default_profiles.json:27](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L27); searched `rg -n -i 'seccomp|landlock|sandbox-exec|bwrap|bubblewrap|firejail|nsjail|gvisor|firecracker'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (No OS sandbox, container or seccomp/landlock wrapper around agents or scripts.) (verified)
  - *To reach the next level:* No sandbox on by default.
- **B L0:** Commands reach the host as the user with credentials in the environment. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642) (verified)
  - *To reach the next level:* Host-equivalent reach with credentials available.
- **Cap:** none
- **Notes:** Codex's own workspace-write sandbox can be selected in a custom profile; it is the runtime's mechanism, not the default agent, and was not credited.

### C5 Untrusted input blast radius: 0.00 (high confidence)

Agents read repository files (with CLAUDE.md and AGENTS.md imported automatically), web content through their own tools, and issue text from the kanban board, with no provenance marking or detection in Vibe Kanban. Because permission prompts are off and the agent holds the user's credentials and network access, injected content can make it exfiltrate secrets and push or delete with no human involved.

- **S L0:** Nothing limits a hijacked agent; prompts are disabled and no taint tracking exists. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); searched `rg -n -i 'untrusted|prompt.injection|quarantin'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 0 hits (No provenance, taint or quarantine handling for content agents read.) (verified)
  - *To reach the next level:* No approval or capability limit once untrusted content is read.
- **C L0:** Untrusted sources are not distinguished from the user's instructions. Evidence: [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016); searched `rg -n -i 'untrusted|prompt.injection|quarantin'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 0 hits (No provenance, taint or quarantine handling for content agents read.) (verified)
  - *To reach the next level:* Untrusted sources are not distinguished.
- **D L0:** No limiting control exists to be on by default. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); searched `rg -n -i 'untrusted|prompt.injection|quarantin'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 0 hits (No provenance, taint or quarantine handling for content agents read.) (verified)
  - *To reach the next level:* No control on by default.
- **B L0:** A hijacked agent can leak secrets from the environment and push or delete unattended. Evidence: [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/git-host/src/github/cli.rs:243](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/git-host/src/github/cli.rs#L243) (verified)
  - *To reach the next level:* Exfiltration and irreversible actions both happen without a human.
- **Cap:** C5-WORSTCASE: Worst case (B L0): a hijacked agent can leak data and take irreversible actions unattended.

### C6 Memory, context & configuration integrity: 0.10 (high confidence)

Agents run in a worktree of the user's repository with their permission prompts disabled, and Vibe Kanban writes workspace CLAUDE.md and AGENTS.md files that import the repository's own instruction files. Vibe Kanban has no workspace-trust decision of its own, so repository-controlled agent settings, hooks and MCP definitions are left to runtimes that have been told not to ask. Agent sessions are resumed across turns. With the opt-in Vibe Kanban MCP server, an agent can also rewrite the setup and dev-server scripts that run in later workspaces.

- **S L0:** Repository-controlled instruction and settings files load with no trust step, in runtimes launched with prompts disabled. Evidence: [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016); [crates/db/src/models/session.rs:186-187](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/db/src/models/session.rs#L186-L187); [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6); searched `rg -n -i 'workspace.trust|trusted.folder|trust.folder'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (Vibe Kanban has no workspace-trust decision of its own before launching agents in a repository.) (verified)
  - *To reach the next level:* No workspace-trust decision before repository config is loaded.
- **C L0:** No memory or config path is controlled by Vibe Kanban. Evidence: [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016); searched `rg -n -i 'workspace.trust|trusted.folder|trust.folder'` in `crates/executors crates/local-deployment crates/services/src` → 0 hits (Vibe Kanban has no workspace-trust decision of its own before launching agents in a repository.) (verified)
  - *To reach the next level:* No memory or config path is controlled.
- **D L1:** Workspaces and sessions are separated per task for a single local user, but nothing stops the agent writing into shared repository files that later sessions load. Evidence: [crates/db/src/models/session.rs:186-187](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/db/src/models/session.rs#L186-L187); [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016) (verified)
  - *To reach the next level:* No enforced isolation of persisted context between sessions.
- **B L1:** Poisoned repository instructions persist across the user's later sessions and can trigger tool use with prompts disabled. Evidence: [crates/local-deployment/src/container.rs:1013-1016](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1013-L1016); [crates/mcp/src/task_server/tools/repos.rs:130](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/mcp/src/task_server/tools/repos.rs#L130) (verified)
  - *To reach the next level:* Poisoned context persists and triggers tool use.
- **Cap:** C6-REPOCONFIG: Files in the repository the agent works on can enable hooks, tools or MCP servers in the launched runtime without a user trust decision, because the runtime is started headless in the worktree with prompts disabled (runtime behaviour inferred from the documented behaviour of Claude Code, Gemini CLI and Codex).

### C7 Third-party extensions: 0.20 (high confidence)

The agent CLIs themselves are downloaded and run through npx at launch, most at pinned versions but Amp at @latest, with no integrity check beyond npm's. The built-in MCP catalog adds servers with unpinned or @latest npx commands, written to the user's agent configuration after an explicit add. Cursor's user-scope MCP servers are pre-approved for each worktree. Every extension runs as the user with the full environment.

- **S L1:** MCP catalog entries and the Amp CLI are unpinned or @latest; other agent CLIs are version-pinned without integrity checks. Evidence: [crates/executors/default_mcp.json:3-7](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_mcp.json#L3-L7); [crates/executors/default_mcp.json:18-21](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_mcp.json#L18-L21); [crates/executors/src/executors/amp.rs:37](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/amp.rs#L37); [crates/executors/src/executors/claude.rs:61-65](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L61-L65); searched `rg -n -i 'sha256|integrity|checksum'` in `crates/executors/src` → 2 hits (Both hits are in cursor/mcp.rs, where a hash names an MCP approval key; nothing verifies the integrity of an agent CLI or MCP server package.) (verified)
  - *To reach the next level:* Extensions are not version-pinned.
- **C L1:** Agent CLIs are pinned (mostly); MCP servers are not verified. Evidence: [crates/executors/src/executors/claude.rs:61-65](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L61-L65); [crates/executors/default_mcp.json:3-7](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_mcp.json#L3-L7) (verified)
  - *To reach the next level:* MCP servers are not verified at all.
- **D L1:** Agent CLIs are fetched automatically on first use; MCP servers are added explicitly to user scope, but runtimes launched with prompts disabled may load repository-defined servers. Evidence: [crates/executors/src/executors/claude.rs:61-65](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L61-L65); [crates/executors/src/executors/claude.rs:597-598](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L597-L598); [crates/executors/default_profiles.json:6](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/default_profiles.json#L6) (verified)
  - *To reach the next level:* Third-party code is fetched automatically on first use with no package-level consent.
- **B L0:** Extensions run as the same user with the agent's full environment and credentials. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642) (verified)
  - *To reach the next level:* No separate process environment or sandbox per extension.
- **Cap:** none

### C8 Secrets & sensitive-data protection: 0.20 (high confidence)

Vibe Kanban's own cloud login is stored in a file readable only by the user, but agents and scripts receive the whole inherited environment, including any API keys and tokens, and nothing is redacted in stored agent logs. Error reporting to Sentry is initialised at startup in release builds without a consent check, with log lines attached as breadcrumbs, and product analytics are on until the user opts out. A leaked key is typically long-lived and broad.

- **S L1:** Secrets come from the environment and the user's CLI logins; only the cloud credential file is protected (mode 0600). Evidence: [crates/services/src/services/oauth_credentials.rs:107](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/oauth_credentials.rs#L107); searched `rg -n -i 'redact|scrub|mask_secret'` in `crates/executors crates/local-deployment crates/services/src crates/utils/src crates/server/src` → 0 hits (No redaction of secrets in logs, stored transcripts or telemetry in the local app.) (verified)
  - *To reach the next level:* No type-level masking or log filters.
- **C L1:** Only stored cloud credentials are protected; subprocess environments, logs, transcripts and telemetry are not. Evidence: [crates/services/src/services/oauth_credentials.rs:107](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/oauth_credentials.rs#L107); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642); searched `rg -n -i 'redact|scrub|mask_secret'` in `crates/executors crates/local-deployment crates/services/src crates/utils/src crates/server/src` → 0 hits (No redaction of secrets in logs, stored transcripts or telemetry in the local app.) (verified)
  - *To reach the next level:* Logs and transcripts are not protected.
- **D L1:** Error reporting starts unconditionally in release builds and analytics default to on. Evidence: [crates/server/src/main.rs:39](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/server/src/main.rs#L39); [crates/utils/src/sentry.rs:99-102](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/sentry.rs#L99-L102); [crates/services/src/services/config/versions/v8.rs:144](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/config/versions/v8.rs#L144) (verified)
  - *To reach the next level:* Telemetry is on by default; it should be opt-in.
- **B L0:** Long-lived, high-privilege keys in the environment are reachable by the model and every subprocess. Evidence: [crates/local-deployment/src/container.rs:1359-1367](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1359-L1367); [crates/executors/src/executors/claude.rs:640-642](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude.rs#L640-L642) (verified)
  - *To reach the next level:* Long-lived, broad keys are reachable by every subprocess.
- **Cap:** none

### C9 Audit & traceability: 0.45 (high confidence)

Every agent and script run is recorded as an execution process, and the agent's raw structured output, including tool calls, results and approval requests and responses, is appended line by line to a JSONL file in the app's data directory outside the workspace. The record is written by the same user the agent runs as, so the agent could alter it, and a failure to open the log file is only logged while the run continues. There is no actor attribution beyond the session and no tamper evidence.

- **S L2:** Structured per-process JSONL of agent output, including tool calls and approval events. Evidence: [crates/utils/src/execution_logs.rs:49-51](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/execution_logs.rs#L49-L51); [crates/utils/src/execution_logs.rs:18-22](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/execution_logs.rs#L18-L22); [crates/executors/src/executors/claude/client.rs:82-86](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude/client.rs#L82-L86) (verified)
  - *To reach the next level:* No actor attribution separating agent, requesting user and approver.
- **C L2:** All agent runs and scripts are recorded as far as each runtime reports its tool calls; sub-agent and MCP calls depend on the runtime. Evidence: [crates/utils/src/execution_logs.rs:49-51](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/execution_logs.rs#L49-L51); [crates/executors/src/executors/claude/client.rs:82-86](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/executors/src/executors/claude/client.rs#L82-L86) (verified)
  - *To reach the next level:* Extension and sub-agent calls are only recorded when the runtime reports them.
- **D L2:** On by default and stored outside the workspace, but in a directory the agent's user can write. Evidence: [crates/utils/src/execution_logs.rs:18-22](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/execution_logs.rs#L18-L22) (verified)
  - *To reach the next level:* The record is writable by the agent's own user.
- **B L1:** Best-effort: if the writer cannot be created the run continues with only an error log. Evidence: [crates/services/src/services/execution_process.rs:263-272](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/services/src/services/execution_process.rs#L263-L272) (verified)
  - *To reach the next level:* Records are not durable per action and failures don't stop actions.
- **Cap:** none

### C10 Limits & kill switch: 0.00 (high confidence)

Vibe Kanban sets no turn, time or cost limit on agent runs, and the runtimes are launched without their own turn caps. The stop button works well: it signals the agent's whole process group with SIGINT, then SIGTERM, then SIGKILL. Nothing bounds how long or how much a runaway agent can spend before someone presses it.

- **S L0:** No step, time or cost limit; only a manual stop that kills the process group. Evidence: searched `rg -n -i 'max.turns|max_iterations|max_cost|cost_limit'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 1 hits (The single hit passes --max-turns to a short slash-command discovery call, not to agent runs.); [crates/utils/src/process.rs:13](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/process.rs#L13) (verified)
  - *To reach the next level:* No iteration, time or cost cap.
- **C L0:** Limits apply to nothing. Evidence: searched `rg -n -i 'max.turns|max_iterations|max_cost|cost_limit'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 1 hits (The single hit passes --max-turns to a short slash-command discovery call, not to agent runs.) (verified)
  - *To reach the next level:* No limits to apply to any path.
- **D L0:** Unlimited by default. Evidence: searched `rg -n -i 'max.turns|max_iterations|max_cost|cost_limit'` in `crates/executors/src crates/local-deployment/src crates/services/src` → 1 hits (The single hit passes --max-turns to a short slash-command discovery call, not to agent runs.) (verified)
  - *To reach the next level:* Unlimited by default.
- **B L0:** No ceiling: a runaway agent can spend and act until a human stops it; the stop itself does kill the whole process group. Evidence: [crates/local-deployment/src/container.rs:1448](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/local-deployment/src/container.rs#L1448); [crates/utils/src/process.rs:13](https://github.com/BloopAI/vibe-kanban/blob/d5cbb5380fa0b32e98ef9b8d987f63decce4be3a/crates/utils/src/process.rs#L13) (verified)
  - *To reach the next level:* No ceiling on spend or run time.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Repository files and imported CLAUDE.md/AGENTS.md (crates/local-deployment/src/container.rs:1013-1016), issue text and the runtimes' web tools · [B] sensitive data/systems: Full inherited environment and CLI logins (crates/local-deployment/src/container.rs:1359-1367; crates/executors/src/executors/claude.rs:640-642) · [C] state change / egress: Shell, git push and PR creation with prompts disabled (crates/executors/default_profiles.json:6; crates/git-host/src/github/cli.rs:243) · Same default session? Yes

## Highest-impact improvements
1. Ship the default agent profiles with the 'Ask' approval mode on and make prompt-skipping an explicitly named opt-in. (C2 D L0→L3, +0.150 before caps; Playbook 5)
2. Pass agents and scripts a minimal allowlisted environment instead of the full inherited one. (C8 C L1→L2, +0.075 before caps; Playbook 4)
3. Add per-run turn and wall-clock caps, enforced by killing the process group. (C10 S L0→L2, +0.150 before caps; Playbook 3 step 3)
4. Run each workspace's agent in a container or OS sandbox limited to its worktree. (C4 S L0→L3, +0.225 before caps; Playbook 3)
5. Make error reporting and analytics opt-in and keep log content out of breadcrumbs. (C8 D L1→L2, +0.050 before caps; Playbook 4)

## Re-audit log
- C10 S: L1 → L0. The process-group stop is real, but no iteration, time or cost limit exists; between anchors, the lower level applies.
- C9 B: L2 → L1. Log writes are not flushed or checked per action; a failure to open the log file only logs an error and the run continues.
- C2 C: L3 → L2. Opt-in approval mode: four executors use the auto-approving no-op service and calls without a tool ID are allowed (alt mechanism).

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- The agent runtimes Vibe Kanban launches (Claude Code, Codex, Gemini CLI and others) were not audited; their handling of repository settings, hooks and MCP definitions is inferred from their documented behaviour.
- The self-hosted cloud server (crates/remote), the relay and remote-access path, the Tauri desktop app and the embedded SSH server were not scored in depth; the score covers the local npx deployment.
- How the web UI renders agent output was not fully examined.
- The README states the project is sunsetting.
