This is a pre-1.0 project. Security fixes are applied to the latest main only.
| Version | Supported |
|---|---|
main (latest) |
✅ |
| older tags | ❌ |
Please do not open a public issue for security problems.
Report privately to g.akashvarma@gmail.com (or use GitHub's private vulnerability reporting). Include:
- what the issue is and where (file / config / command),
- a minimal way to reproduce it,
- the impact you think it has.
You'll get an acknowledgement as soon as possible. Please allow a reasonable window for a fix before any public disclosure.
Flow spawns processes and lets agents run tools. That is the whole point, so the risk surface is worth understanding.
-
Subprocess execution. Every agent turn runs the
claudeCLI as a subprocess (src/claude.ts) with its working directory set toprojects/<slug>/workspace/. The subprocess can only use the tools its role declares inteam.json(allowed_tools). Planner roles are read-only (Read/Grep/Glob);developerandqaadditionally getEdit/Write/Bash. QA agents may shell out totools/run_capture.py, which spawns a target program in a pseudo-terminal. -
No secrets are handled by this tool. Flow reads no
.env, accesses noprocess.envsecret, and hardcodes no key or token. All authentication belongs to the Claude Code CLI (your subscription). The only outbound network calls come from theclaudesubprocess itself. -
⚠️ Sandbox mode removes the guardrails on purpose.team.sandbox.jsonsetspermission_mode: "bypassPermissions"and passes--dangerously-skip-permissionstoclaude, so the agent'sBashruns with no confirmation prompts. Pair it with--yes(no human gates) and a run is fully autonomous with shell access. Run it only inside a disposable VM or container, never on a host with data, credentials, or network access you care about. -
Generated output can be sensitive.
projects/andruns/contain generated code, per-run USD cost, and Anthropic session identifiers. They are git-ignored; do not commit them.
A brief is a prompt fed to autonomous agents with tool access. Treat briefs from people you don't trust the same way you'd treat untrusted code: run them in the sandbox, in an isolated environment, and review the artifacts at the gates.