Permissions & safety

Tool calls are Allow / Ask / Deny — your call. Browser capabilities are authorized per domain; sensitive fields are always refused.

The default principle: ask first

Before calling a tool (reading files, running commands, etc.), the agent asks for your approval. The default is Ask:

  • Allow: let it through;
  • Ask (default): show a confirmation for every call;
  • Deny: block the call.

You can adjust the three states per tool in Settings — for example, Allow for "read file", keep Ask for "run command", Deny for dangerous tools. Changes take effect immediately.

Balancing automation and control

Setting frequent, low-risk tools to "Allow" cuts interruptions; calls that delete, overwrite, or execute are worth keeping on "Ask". Every confirmation shows the tool name and parameters — read before you approve.

Browser: per-domain authorization

The embedded browser's agent control is fully off by default, and even when enabled it is authorized per domain (Settings → Chat → Browser control):

  • With the master switch off, the model gets no browser tools at all;
  • With it on, you separately authorize three capabilities: read page content, click elements, and type & submit (typing and submitting have independent switches — "click-only" is a valid choice);
  • Only domains you explicitly add are governed; the agent cannot touch unauthorized pages;
  • Sensitive fields are always refused: password, one-time code, and payment fields are never read or filled;
  • "Type" needs your per-action confirmation (the confirmation bar lives in the browser panel); "submit" happens at most once per domain per session;
  • Audit records keep the domain and outcome only — page content is never stored.

Before installing any third-party extension, the app shows its source, type, and scope of capabilities — nothing installs without your confirmation; external extensions are checked against known malware packages before activation.

Data & audit

  • Permission settings stay on this machine; approvals never send data to any server;
  • Browser operations keep local audit lines (domain + outcome) with no page content or form data — see Privacy & data.

This page is adapted from upstream open-source documentation (Apache-2.0) with modifications; see /legal/provenance for sources and changes.