Skip to content

Security model

How Myko guards files, shells, secrets and the network.

Myko runs shells, reads and writes files, and sends data to AI providers, so each boundary validates input.

Boundaries

  • IPC commands gated by Tauri capabilities
  • AI file tools pass a secret-path deny-list on read and write
  • Terminal and git work only in authorized workspace folders
  • AI network requests go through a native proxy with SSRF and DNS-rebinding defenses
  • API keys live in the OS keychain
  • Terminal escape sequences are parsed but not blindly trusted

Blocked paths

The AI tools refuse files such as .env*, private keys, and credential stores, and directories such as ~/.ssh, ~/.aws and ~/.gnupg.