Security design
Boundaries that hold on every call
StudioCat lets a model act on your machine. We assume the model can be wrong, confused or steered by content it reads — so the boundaries are enforced by StudioCat on every call, not suggested to the model. This page describes the design of the current version.
Threat model
- In scope: a model that calls the wrong tool, targets the wrong path or project, repeats a write, or follows instructions planted in files, web pages or tool output.
- In scope: network exposure of your Mac, and leaking credentials through logs, arguments or diagnostics.
- Out of scope: someone who already controls your macOS account or your ChatGPT account. Anyone who can use your ChatGPT account can use the projects you've approved — protect it with multi-factor authentication.
Transport: outbound only
StudioCat embeds OpenAI's tunnel client. It long-polls OpenAI over HTTPS for tool calls and posts results back. There is no local server, no listening port and no port forwarding; diagnostics never open a listener either. Calls arrive only from the MCP server you added in ChatGPT for your tunnel.
Authorization on every call
- One policy store decides every call, in order: tool → command → path. Tool annotations are hints, never permissions.
- Paths are canonicalized (symlinks,
..) before they're checked; aliases can't bypass a rule, and deny rules win. - Only projects you approved in the app count. Permissions come from your actions in the app — never from the model or from paths it sends.
- Terminal and commits are off by default for every project and are never turned on automatically.
- Inputs are validated strictly: unknown fields and wrong types are rejected, not coerced into a different call.
- Each conversation is bound to its project, so one chat can't quietly act in another project.
Confirmations
Commands matching dangerous patterns ask for confirmation on the Mac after the policy allows them and before anything runs. A denial or a timeout means nothing happened and the model is told so. A confirmation can never widen a boundary: calls the policy denies are refused without asking. The command list is a guard against slips, not the boundary — the boundary is whether a project has the terminal at all.
Changes & recovery
- Patches are applied as a unit per project: if part fails, completed parts are compensated and the failure is reported honestly.
- Every edit is reviewable and can be rolled back from Review Diff; a stale card refuses rather than overwriting newer work.
- Checkpoints use hidden refs and a temporary index — your branch, HEAD, index and stash are untouched.
- Commands are stopped by process group, so a cancelled command doesn't leave children running.
Honest results
Tool errors come back with stable codes (not_authorized, user_denied, conflicts, …). If a call times out
after it may already have run, the model receives outcome_unknown with advice to check state before retrying — never a false
“nothing happened”. Large results are truncated explicitly, never silently.
Credentials & data
- Tunnel credentials live only in your macOS Keychain (or environment variables you set). They never appear in arguments, logs, status files or diagnostic output.
- StudioCat never uploads your repository. What the model reads through tool calls becomes part of your ChatGPT conversation and is handled under OpenAI's terms.
- A local audit log records every allow and deny decision. Nothing is sent to us; there is no telemetry unless a future version asks you to opt in.
Limits
- The policy is not an OS sandbox. A project with the terminal enabled can run whatever your user account can run — enable it only where you'd run commands yourself.
- Checkpoints and rollbacks are not backups and don't cover files git ignores.
- Patch rollback is not atomic across a crash of the Mac.
- StudioCat is closed source today; signed and notarized builds and this document are how we earn trust until that changes.
Reporting issues
Found a security problem? Email [email protected] with “Security report” in the subject. Please don't include API keys or private code.