Permissions & safety
Tool calls are Allow / Ask / Deny — your call. Browser capabilities are authorized per domain; sensitive fields are always refused.
The default principle: ask first
Before calling a tool (reading files, running commands, etc.), the agent asks for your approval. The default is Ask:
- Allow: let it through;
- Ask (default): show a confirmation for every call;
- Deny: block the call.
You can adjust the three states per tool in Settings — for example, Allow for "read file", keep Ask for "run command", Deny for dangerous tools. Changes take effect immediately.
Balancing automation and control
Setting frequent, low-risk tools to "Allow" cuts interruptions; calls that delete, overwrite, or execute are worth keeping on "Ask". Every confirmation shows the tool name and parameters — read before you approve.
Browser: per-domain authorization
The embedded browser's agent control is fully off by default, and even when enabled it is authorized per domain (Settings → Chat → Browser control):
- With the master switch off, the model gets no browser tools at all;
- With it on, you separately authorize three capabilities: read page content, click elements, and type & submit (typing and submitting have independent switches — "click-only" is a valid choice);
- Only domains you explicitly add are governed; the agent cannot touch unauthorized pages;
- Sensitive fields are always refused: password, one-time code, and payment fields are never read or filled;
- "Type" needs your per-action confirmation (the confirmation bar lives in the browser panel); "submit" happens at most once per domain per session;
- Audit records keep the domain and outcome only — page content is never stored.
Extension installs: explicit consent
Before installing any third-party extension, the app shows its source, type, and scope of capabilities — nothing installs without your confirmation; external extensions are checked against known malware packages before activation.
Data & audit
- Permission settings stay on this machine; approvals never send data to any server;
- Browser operations keep local audit lines (domain + outcome) with no page content or form data — see Privacy & data.
This page is adapted from upstream open-source documentation (Apache-2.0) with modifications; see /legal/provenance for sources and changes.