Skip to content

chore: add a prominent README security warning - #207

Merged
iamnbutler merged 1 commit into
mainfrom
codex/readme-security
Oct 7, 2026
Merged

iamnbutler merged 1 commit into
mainfrom
codex/readme-security

Conversation

@iamnbutler

Copy link
Copy Markdown
Contributor

The README now leads with a security notice explaining that agents run with the host user's privileges and that channels and lanes do not sandbox shell or file access. It documents default collaborator invocation, what disabling sharing actually does, and keeping the host gateway private.

Inspired by Collie's security notice, adapted to Ace's trust model.

Validation: checked the claims against Ace's current architecture and CLI; bunx dprint check readme.md and git diff --check passed. Only readme.md changes.

Built in Ace

The edit, formatting checks, commit, push, and PR creation ran in the Ace channel readme-security. Codex was used for the initial request, source browsing, drafting, coordination, and an independent read-only review because Ace cannot yet host this Codex conversation; tracked in #9 under the dogfooding meta issue #5.

@iamnbutler
iamnbutler merged commit 3405ec6 into main Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant