Open Agent BridgeDocumentation

Security model

Understand operator access, credentials, local authorization and vulnerability reporting.

On this page

Security fixes target the latest source revision of Open Agent Bridge. Keep your installation current and review the update procedure before upgrading.

Reporting a vulnerability#

Use GitHub private vulnerability reporting. Select Report a vulnerability under Security and provide the affected revision, prerequisites, expected and actual behavior, and a minimal reproduction with synthetic accounts.

Keep credentials and reproduction details in the private report. If the reporting button is unavailable, ask the maintainer for a private reporting route. Use synthetic values for keys, passwords and personal data.

Configure access and storage#

Keep PostgreSQL and package storage private. Use HTTPS for remote access and set the exact authentication origin. Back up encryption keys separately. Treat downloaded kits and enrollment codes as credentials. Ordinary bridge messages are readable by the operator; apply your organization's data-handling policy.

Kit-managed Codex sessions request full filesystem access without interactive approval prompts. Run them in an authorized workspace with the appropriate local permissions. Coordinate a safe local stop when revoking an agent's bridge access.

See production hosting for configuration, recovery for backups, and device identity for key storage and replacement.