Skip to content

Security: AkashVarma007/Agentic-Company

Security

SECURITY.md

Security Policy

Supported versions

This is a pre-1.0 project. Security fixes are applied to the latest main only.

Version Supported
main (latest) ✅
older tags ❌

Reporting a vulnerability

Please do not open a public issue for security problems.

Report privately to g.akashvarma@gmail.com (or use GitHub's private vulnerability reporting). Include:

  • what the issue is and where (file / config / command),
  • a minimal way to reproduce it,
  • the impact you think it has.

You'll get an acknowledgement as soon as possible. Please allow a reasonable window for a fix before any public disclosure.

Security model — what to know before running

Flow spawns processes and lets agents run tools. That is the whole point, so the risk surface is worth understanding.

  • Subprocess execution. Every agent turn runs the claude CLI as a subprocess (src/claude.ts) with its working directory set to projects/<slug>/workspace/. The subprocess can only use the tools its role declares in team.json (allowed_tools). Planner roles are read-only (Read/Grep/Glob); developer and qa additionally get Edit/Write/Bash. QA agents may shell out to tools/run_capture.py, which spawns a target program in a pseudo-terminal.

  • No secrets are handled by this tool. Flow reads no .env, accesses no process.env secret, and hardcodes no key or token. All authentication belongs to the Claude Code CLI (your subscription). The only outbound network calls come from the claude subprocess itself.

  • ⚠️ Sandbox mode removes the guardrails on purpose. team.sandbox.json sets permission_mode: "bypassPermissions" and passes --dangerously-skip-permissions to claude, so the agent's Bash runs with no confirmation prompts. Pair it with --yes (no human gates) and a run is fully autonomous with shell access. Run it only inside a disposable VM or container, never on a host with data, credentials, or network access you care about.

  • Generated output can be sensitive. projects/ and runs/ contain generated code, per-run USD cost, and Anthropic session identifiers. They are git-ignored; do not commit them.

Untrusted briefs

A brief is a prompt fed to autonomous agents with tool access. Treat briefs from people you don't trust the same way you'd treat untrusted code: run them in the sandbox, in an isolated environment, and review the artifacts at the gates.

There aren't any published security advisories