Menteus executes actions on a user's machine. Treat every issue in this repo as a security issue until proven otherwise.
Do not open a public issue for a vulnerability. Email security@example.com with steps to reproduce. You will get an acknowledgement within 72 hours.
The agent is driven by a model that reads content it did not write: web pages, documents, emails. Prompt injection is not hypothetical here, it is the primary threat. The defence is not the model, it is the permission layer:
- Capabilities are allow / ask / block per user policy, enforced in
packages/permissions/src/policy.tsbefore a tool runs. - Filesystem access is confined to allowlisted roots (
sandbox.ts). - Irreversible or outward-facing actions (sending mail, posting, paying, deleting outside a workspace) default to ask, always.
- Every call is written to an append-only audit log before it executes.
The renderer runs with contextIsolation: true, nodeIntegration: false, and
sandbox: true. It reaches the agent only through the typed preload bridge in
apps/desktop/src/preload.ts, never through direct Node access. Anything the
UI can trigger is a named channel with a validated payload.
Installers are built in CI from a tagged commit and published as GitHub release assets. Auto-update checks signatures before applying. Do not distribute builds from a developer machine.
Running Menteus with every capability set to allow, then being surprised. The interface makes the posture visible for a reason.