Security
Last updated 9 September 2026
The honest framing. FORGE gives a language model real tools on your real computer. That is the product, and it is the risk. Everything below exists to make sure the model can only do what you agreed to — and to be clear about where that guarantee ends.
A permission for every tool
Each tool is allow, ask or deny, and you set them. Reading is allowed by default; writing and editing ask; shell commands ask and additionally run through regex rules where the last match wins, with dangerous patterns denied outright — recursive deletes, disk formatting, privilege escalation, piping the internet into a shell.
A tool set to deny is not merely blocked: the model never sees it, so it cannot plan around a capability it does not know exists.
A folder it cannot leave
Every file tool resolves against your workspace and refuses anything that
escapes it, including symlinks and .. traversal. Beside the message
box there is one switch that turns file and shell access off entirely — with it
off, the model cannot see those tools at all, while chat, web search and
research keep working.
Local means local
The control API — the one that edits files and runs commands — binds to
127.0.0.1 and answers only your own machine. There is no token
that unlocks it remotely, on purpose. It also checks the Host
header, so a hostile web page whose DNS points at your loopback address is
refused, and it rejects writes carrying a foreign Origin, which
is what a browser attaches when a page tries to POST to localhost on your
behalf.
Only the OpenAI-compatible /v1 endpoint can be exposed to
your network, it is off by default, and it is token-guarded. It forwards
prompts to the model and nothing else: the agent, your files and your shell
are never reachable that way.
Browser, desktop and admin control
FORGE can drive a real browser, control your actual desktop — screenshot, mouse, keyboard — and run commands as administrator. These are genuinely dangerous and are treated that way: off by default, each requires you to type I UNDERSTAND to enable, all are revoked when FORGE exits, and they are invisible to the model until granted.
Once granted, the model is acting as you. Treat a task with desktop control the way you would treat handing someone your keyboard.
Nothing is installed without being checked
Every byte FORGE downloads is verified before it is written:
- Updates are checked against a published SHA-256; a file that does not match is not written, the helper rechecks immediately before setup, and the whole update is verified before anything is replaced
- Models are checked against the digest their host publishes — and a file with no published digest is refused rather than downloaded blind
- Skills and library entries are hash-pinned in the verified tier
- The image engine and its extractor are pinned by hash and by exact byte count, from their official sources
Each update operation keeps its phase, installer exit status and diagnostic receipt outside the transient download cache, so a failed or interrupted update can be inspected and recovered without guessing whether it already ran.
The installer itself publishes its SHA-256 on the download page so you can check what you downloaded before you run it.
Prompt injection
A web page or a file the agent reads can contain text telling it to do something. FORGE's system prompt instructs the model to treat fetched content as data rather than instructions — but no model is immune to this, and we are not going to claim otherwise. The real protection is the permission engine: an injected instruction still has to get past a prompt you answer.
What we do not claim
- Account linking is optional for the local workstation. Any future hosted entitlement would be a licensing statement, not a security boundary — its verification code ships inside an app that runs on your machine
- The installer is not yet code-signed, so Windows will warn about an unknown publisher. Verify the SHA-256 in the meantime; a certificate is on the way
- Local software cannot protect you from yourself: auto-approve exists, and turning it on means the agent stops asking
Reporting something
Found a vulnerability? Email kevinklubeck@gmail.com with enough detail to reproduce it. Please give us a chance to fix it before publishing. There is no bounty programme yet, but you will be credited if you want to be.