BoundBench

QwenPaw

Personal AI assistant built on AgentScope with a local web console, terminal UI, chat-channel integrations, skills, plugins and MCP support.

github.com/agentscope-ai/QwenPaw · 2026-10-05 · 80e412d

Defense-in-depth score

2.3 / 10

Minimal

As shipped, QwenPaw runs shell commands on your machine as your user, with no sandbox and no approval prompt unless a built-in dangerous-command pattern fires, and it can fetch any web page, so content it reads can steer it into reading your files and sending them out. It has a substantial governance layer (approval cards showing the exact call, a policy engine that fails closed, an audit database and an OS sandbox), but the sandbox is off by default and the default approval level leaves the shell ungated. Turn on the sandbox, use the STRICT approval level and run it under a dedicated OS user.

Key gaps (6)

  1. Shell commands run without approval in the default configuration unless a dangerous-command pattern or sensitive-path check fires. C2 · Approval gates
  2. The approval level can be loosened at runtime from inside a session, without an operator-level change. C2 · Approval gates
  3. A hijacked default session can read local files and send them out, and run irreversible commands, with no human involved. C5 · Untrusted input blast radius
  4. The agent runs with the launching user's full authority and environment. C1 · Identity & least privilege
  5. Shell commands run as host subprocesses by default because the sandbox switch ships off. C4 · Code-execution isolation
  6. Marketplace plugins are imported into the agent's own process with no integrity check. C7 · Third-party extensions

Criteria

C1 Identity & least privilege

Minimal 0.07 / 1.00

QwenPaw runs as the operating-system user who starts it and does nothing to narrow that authority: shell commands inherit the full process environment, including any keys you add through its environment manager, and there is no per-tool or per-request credential. The governance layer decides which actions run, but it does not scope identities. Its own security policy tells operators to give it a dedicated OS user or host; nothing in the default install does that for you. If the agent is steered, it acts with everything your account can reach.

C2 Approval gates

Minimal 0.25 / 1.00

QwenPaw has a real approval system: a policy engine asks a human before risky calls, the approval card shows the exact tool input, unknown tools are denied and a governance start-up failure denies everything. But at the default approval level, shell commands run immediately unless one of the built-in dangerous-command patterns or sensitive-path checks fires, so the most powerful tool is effectively ungated. The approval level can also be changed at runtime without an operator-level step. There are no default checkpoints, so most actions can't be undone.

C3 Tool & action scoping

Minimal 0.28 / 1.00

The tools are general purpose: a raw shell, file tools that deliberately don't confine paths, and a web fetcher that takes any http(s) URL and follows redirects without blocking internal addresses. What validation exists is a denylist of dangerous shell patterns and glob rules on the target path, which mostly allow. Shell, file write, browser and web tools are all on by default, though each can be switched off in the console. A misused tool can reach anything the user can.

C4 Code-execution isolation

Minimal 0.28 / 1.00

By default shell commands run as ordinary host subprocesses with the full environment, because the global sandbox switch ships off and the governance layer then runs them unsandboxed without asking. An OS sandbox exists (Bubblewrap or Landlock on Linux, Seatbelt on macOS, AppContainer on Windows) that limits writes to the workspace, but it leaves the network open, passes most of the environment through, covers only the shell and the recall REPL, and is skipped silently when the platform can't provide it. Turning it on is worthwhile but does not make the shell a contained environment.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

The agent reads web pages, search results, files, browser content and MCP results, and none of it is marked or handled differently from the user's own instructions; the only defence is a system-prompt line telling the model to treat such content as data. In the default configuration a hijacked agent can read the user's files, run shell commands and send data out through the web fetcher or the shell, all without a human. The project's own security policy says the model is not a trusted principal and treats prompt injection as out of scope unless it crosses a boundary, but the default boundaries are wide.

C6 Memory, context & configuration integrity

Minimal 0.10 / 1.00

Each agent's workspace holds instruction files (AGENTS.md, SOUL.md, PROFILE.md) that are loaded into the system prompt on every turn, plus MEMORY.md and the ReMe knowledge base. The agent's file tools may write anything inside its workspace without asking, so content it reads in one session can rewrite the instructions every later session follows. QwenPaw does not load instruction or config files from the projects you point it at, and memory lives per agent, but there is no validation, provenance or review step for memory writes and automatic checkpoints are off.

C7 Third-party extensions

Minimal 0.17 / 1.00

QwenPaw loads three kinds of third-party code: plugins from its marketplace, which are imported into the main process; skills, which run with the process's privileges and are only scanned in warn mode; and MCP servers, which the user adds and whose calls ask for approval by default. Nothing third-party is verified: plugin archives are installed without checking the catalog's listed hash, and the shipped external-agent entries launch npm packages at whatever version is latest, though the tool that uses them is off by default. A malicious plugin gets everything the agent has.

C8 Secrets & sensitive-data protection

Minimal 0.28 / 1.00

Stored secrets are encrypted with a master key kept in the OS keychain or a 0600 file, and the secret directory is on the file guard's protected list. But environment variables configured through QwenPaw are injected into the process environment and reach every shell subprocess, there is no general redaction before content goes to logs or the model, and a daily content-free usage ping is on unless you opt out. Anything a key can do, a hijacked shell can do with it.

C9 Audit & traceability

Moderate 0.50 / 1.00

Every governed tool decision, including user approvals and denials, is written immediately to a SQLite audit log under the QwenPaw home directory with time, agent, session, tool, target and decision. It is on by default and sits outside the agent's workspace, but the unsandboxed shell can still edit it and the policy file can turn it off. Calls to MCP servers go through a separate driver path that doesn't write to this log, and the record keeps the target rather than full arguments or results.

C10 Limits & kill switch

Minimal 0.40 / 1.00

Runs stop after 100 reasoning steps by default, a repetition detector is on, shell commands default to 60-second timeouts, and cancelling a command kills its whole process group. There is no default token or cost cap (a token-budget gate exists only in custom loop modes), the model can ask for longer shell timeouts up to a 24-hour ceiling, sub-agents start their own step budgets, and scheduled jobs keep running after a chat is stopped.