Report vulnerabilities privately through GitHub: Security → Report a vulnerability. Private reporting is enabled on this repository. Please do not open a public issue for anything exploitable.
Ambit is a personal project, not a staffed one — expect a first response in days rather than hours.
Ambit reads your agent configuration and, through the visualizer, writes back to it. Four invariants hold that surface, and a break in any of the four is a vulnerability. AGENTS.md says where each of the four is enforced in code.
- Loopback only. The API server binds
127.0.0.1. Nothing on your LAN and nothing through a tunnel can reach it, and any path that widens that bind is in scope. - Origin allowlist. A request with a non-local
Originis rejected with 403 before routing. CORS headers alone would be insufficient, because a simple request skips preflight and reaches the handler regardless. Anything that lets a page you visit reach the API is in scope. - No entry creation over HTTP. An MCP entry carries a command your agent runtime executes, so creating one over HTTP would be remote code execution. The API can toggle an existing MCP server's
enabled, edit an existing agent'sdescriptionormodel, and edit an existing command'sdescription; adding a server produces a snippet you paste yourself. Any path that turns an HTTP request into a new executable config entry is in scope. - No egress you did not type. The graph is a local SQLite file and there is no telemetry. The only outbound calls in the engine are
ambit notifyandambit notify-approvals, each of which needs a topic argument before it sends anything;ambit dispatch(andpropose/approvewith--dispatch), which needs a webhook URL from--toorAMBIT_APPROVAL_WEBHOOKand sends one proposal's summary or signed artifact, never a command;ambit incidents, which probes the service URLs your own manifest names with an empty GET; andambit goal --judge, which sends the goal you typed to a judgment model on this machine and refuses any URL whose host is not127.0.0.1,localhostor[::1], or that carries credentials. The server reads the local Docker socket when one exists, over a unix socket and read-only; that is not egress, and it never starts or stops anything.ambit graph capacityrunstailscale status --json,sysctlandnvidia-smion this machine when you type it, with fixed arguments and no shell; the first asks the local Tailscale daemon, none sends anything, the report leaves out addresses, and nothing is written. The server never runs them. Any other path that moves the graph off the machine is in scope, and an exfiltration path is high severity.
Also in scope: anything that causes the engine to execute content from a scanned configuration or infrastructure manifest.
- The declared verification checks run commands from the capability model by design. That model is code in this repository; changing it is equivalent to changing any other source file.
ambit apply <id>and the visualizer's config editing modify your configuration on purpose, writing a.bakfirst.- Findings against a fork's own capability model, or against a configuration you supplied yourself, are not vulnerabilities in Ambit.
The graph is a local SQLite file whose path ambit where prints, and it describes your machines, your credentials-adjacent tooling, and your network reach. ambit graph and ambit status describe your machine too, so redact before pasting either into a report; the FAQ lists the commands that can move data and what each one sends.