Security model
How Myko guards files, shells, secrets and the network.
Myko runs shells, reads and writes files, and sends data to AI providers, so each boundary validates input.
Boundaries
- IPC commands gated by Tauri capabilities
- AI file tools pass a secret-path deny-list on read and write
- Terminal and git work only in authorized workspace folders
- AI network requests go through a native proxy with SSRF and DNS-rebinding defenses
- API keys live in the OS keychain
- Terminal escape sequences are parsed but not blindly trusted
Blocked paths
The AI tools refuse files such as .env*, private keys, and credential stores, and directories such as ~/.ssh, ~/.aws and ~/.gnupg.