Security design

Boundaries that hold on every call

StudioCat lets a model act on your machine. We assume the model can be wrong, confused or steered by content it reads — so the boundaries are enforced by StudioCat on every call, not suggested to the model. This page describes the design of the current version.

Threat model

Transport: outbound only

StudioCat embeds OpenAI's tunnel client. It long-polls OpenAI over HTTPS for tool calls and posts results back. There is no local server, no listening port and no port forwarding; diagnostics never open a listener either. Calls arrive only from the MCP server you added in ChatGPT for your tunnel.

Authorization on every call

Confirmations

Commands matching dangerous patterns ask for confirmation on the Mac after the policy allows them and before anything runs. A denial or a timeout means nothing happened and the model is told so. A confirmation can never widen a boundary: calls the policy denies are refused without asking. The command list is a guard against slips, not the boundary — the boundary is whether a project has the terminal at all.

Changes & recovery

Honest results

Tool errors come back with stable codes (not_authorized, user_denied, conflicts, …). If a call times out after it may already have run, the model receives outcome_unknown with advice to check state before retrying — never a false “nothing happened”. Large results are truncated explicitly, never silently.

Credentials & data

Limits

Reporting issues

Found a security problem? Email [email protected] with “Security report” in the subject. Please don't include API keys or private code.