Skip to content

Security: pdparchitect/noodle

Security

SECURITY.md

Security notice

Noodle agents can run commands, change files, and use connected services. Give them access appropriate to the work you want done.

Agent access

The Noodle app is sandboxed, but agents with unrestricted access run outside that sandbox as your Mac user. They can access files and signed-in services beyond their workspace. Noodle accepts supported tool approvals automatically.

Configure each bot’s access in Settings → Sandbox. Click the Unrestricted heading or a bot's restricted or unrestricted label for an explanation.

Data and credentials

Conversations and workspaces are stored locally. Your harness sends work to its model provider; connected tools can send data to their services. Local storage does not make model processing local.

Noodle stores connected-tool credentials in Keychain. Voice transcription runs on your Mac; sending a voice message shares its audio and transcript with the agents.

Shared computers

Noodle Computer runs Linux workspaces in virtual machines without sharing host folders or the clipboard. Agents assigned to the same computer share its files and services. Guest networking can reach your LAN.

Updates

Public app releases are signed and notarized. In-app updates verify signed archives before installation.

See agent access and privacy for access controls and revocation.

There aren't any published security advisories