Skip to content

Security: Omlin/Menteus

Security

SECURITY.md

Security

Menteus executes actions on a user's machine. Treat every issue in this repo as a security issue until proven otherwise.

Reporting

Do not open a public issue for a vulnerability. Email security@example.com with steps to reproduce. You will get an acknowledgement within 72 hours.

Threat model

The agent is driven by a model that reads content it did not write: web pages, documents, emails. Prompt injection is not hypothetical here, it is the primary threat. The defence is not the model, it is the permission layer:

  • Capabilities are allow / ask / block per user policy, enforced in packages/permissions/src/policy.ts before a tool runs.
  • Filesystem access is confined to allowlisted roots (sandbox.ts).
  • Irreversible or outward-facing actions (sending mail, posting, paying, deleting outside a workspace) default to ask, always.
  • Every call is written to an append-only audit log before it executes.

Desktop hardening

The renderer runs with contextIsolation: true, nodeIntegration: false, and sandbox: true. It reaches the agent only through the typed preload bridge in apps/desktop/src/preload.ts, never through direct Node access. Anything the UI can trigger is a named channel with a validated payload.

Releases

Installers are built in CI from a tagged commit and published as GitHub release assets. Auto-update checks signatures before applying. Do not distribute builds from a developer machine.

Out of scope

Running Menteus with every capability set to allow, then being surprised. The interface makes the posture visible for a reason.

There aren't any published security advisories