Security

Bound the analysis. Verify the evidence.

Repository and provider boundary

CodeCaddie freezes one exact commit into a disposable, history-free snapshot. Provider tools are read-only and path-confined, live symlinks are excluded, the original checkout is not modified, and process descendants are terminated on timeout or cancellation.

Provider output is treated as untrusted. Structured responses and evidence coordinates are validated before persistence; source-matching narrative is replaced with neutral wording or rejected. Invalid goal generation fails visibly instead of inserting generic fallback goals.

Document boundary

Selected product documents are parsed by the local core with file-count, file-size, combined-size, and extracted-character limits. Unsupported, corrupt, encrypted, image-only, empty, symlinked, missing, or changed documents fail closed. Extracted text is sent only to the chosen provider for goal generation and is never stored in application state or logs.

Release trust

Stable desktop artifacts are signed by their operating-system publisher identity. The app additionally verifies a signed release manifest, SHA-256 artifact digest, platform, architecture, and downgrade policy before offering installation. Download and installation remain explicit user actions.

Report vulnerabilities privately

Use GitHub private vulnerability reporting. Do not open a public issue containing exploit details, repository information, provider credentials, private paths, recovery exports, or customer data.