Trust boundary

Security

CodeLocal separates AI reasoning, cloud coordination and local execution so that access remains scoped to explicitly authorized workspaces and guarded actions.

Publisher: CodeLocal ·

Execution boundary

Filesystem, Git, terminal, browser and desktop execution occur through a paired CodeLocal runtime. Workspaces must be explicitly authorized. The Cloud gateway routes authenticated requests but does not turn the entire computer into a remotely browsable filesystem.

Approval model

Potentially destructive, open-world or otherwise sensitive operations are classified by policy and may require user confirmation. Approval tokens are scoped and must not be treated as reusable credentials.

MCP metadata

The public plugin exposes a compact MCP tool surface with explicit read-only, destructive and open-world annotations. CodeLocal treats annotations as review metadata; local security policy and user approval remain authoritative.

Report a vulnerability

Send security reports to k58a01.mmh@gmail.com. Include reproduction steps and impact, but never include real user credentials or unrelated private data.