FORGE

Security

Last updated 9 September 2026

The honest framing. FORGE gives a language model real tools on your real computer. That is the product, and it is the risk. Everything below exists to make sure the model can only do what you agreed to — and to be clear about where that guarantee ends.

A permission for every tool

Each tool is allow, ask or deny, and you set them. Reading is allowed by default; writing and editing ask; shell commands ask and additionally run through regex rules where the last match wins, with dangerous patterns denied outright — recursive deletes, disk formatting, privilege escalation, piping the internet into a shell.

A tool set to deny is not merely blocked: the model never sees it, so it cannot plan around a capability it does not know exists.

A folder it cannot leave

Every file tool resolves against your workspace and refuses anything that escapes it, including symlinks and .. traversal. Beside the message box there is one switch that turns file and shell access off entirely — with it off, the model cannot see those tools at all, while chat, web search and research keep working.

Local means local

The control API — the one that edits files and runs commands — binds to 127.0.0.1 and answers only your own machine. There is no token that unlocks it remotely, on purpose. It also checks the Host header, so a hostile web page whose DNS points at your loopback address is refused, and it rejects writes carrying a foreign Origin, which is what a browser attaches when a page tries to POST to localhost on your behalf.

Only the OpenAI-compatible /v1 endpoint can be exposed to your network, it is off by default, and it is token-guarded. It forwards prompts to the model and nothing else: the agent, your files and your shell are never reachable that way.

Browser, desktop and admin control

FORGE can drive a real browser, control your actual desktop — screenshot, mouse, keyboard — and run commands as administrator. These are genuinely dangerous and are treated that way: off by default, each requires you to type I UNDERSTAND to enable, all are revoked when FORGE exits, and they are invisible to the model until granted.

Once granted, the model is acting as you. Treat a task with desktop control the way you would treat handing someone your keyboard.

Nothing is installed without being checked

Every byte FORGE downloads is verified before it is written:

Each update operation keeps its phase, installer exit status and diagnostic receipt outside the transient download cache, so a failed or interrupted update can be inspected and recovered without guessing whether it already ran.

The installer itself publishes its SHA-256 on the download page so you can check what you downloaded before you run it.

Prompt injection

A web page or a file the agent reads can contain text telling it to do something. FORGE's system prompt instructs the model to treat fetched content as data rather than instructions — but no model is immune to this, and we are not going to claim otherwise. The real protection is the permission engine: an injected instruction still has to get past a prompt you answer.

What we do not claim

Reporting something

Found a vulnerability? Email kevinklubeck@gmail.com with enough detail to reproduce it. Please give us a chance to fix it before publishing. There is no bounty programme yet, but you will be credited if you want to be.