C1 Identity & least privilege
Minimal 0.00 / 1.00
Swarms agents run with whatever authority the hosting Python process has. LLM provider keys come from environment variables (including any .env found above the working directory), and the autonomous mode's shell tool and every stdio MCP server inherit the full process environment. There is no per-tool identity, no scoped credential, and no authorization check anywhere on the tool path, so a hijacked agent acts with the operator's full local and cloud authority.
C2 Approval gates
Minimal 0.00 / 1.00
There is no human approval step anywhere in the framework. The tool executor calls registered Python functions directly, the autonomous mode runs shell commands, writes and deletes files, and spawns sub-agents without asking anyone, and MCP tool calls go straight to the server. Interactive mode only asks the human for the next task, not for permission to act.
C3 Tool & action scoping
Minimal 0.05 / 1.00
Built-in tools are general-purpose and unbounded. The autonomous mode's file tools accept absolute paths and simply use them, so create, update, read and delete reach anywhere the process can, and run_bash accepts an arbitrary shell string. The framework passes model arguments to user tools without validating them against the schema. Developers can narrow the autonomous tool set with selected_tools, but the default is every tool.
C4 Code-execution isolation
Minimal 0.20 / 1.00
Model-written shell commands in autonomous mode run directly on the host with shell=True, in the process's working directory, with the full inherited environment. The only control is a substring denylist that is not a strict boundary. No container or OS sandbox exists anywhere in the framework, and stdio MCP servers also launch on the host.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Tool results, MCP results and other agents' messages are appended to the conversation and sent back to the model with no marking or restriction. Nothing in the framework distinguishes untrusted content or limits what the agent can do after reading it. In autonomous mode a single session combines reading files and tool output, holding the user's credentials, and running shell commands with network access, so an injected instruction can both exfiltrate secrets and take destructive action with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.05 / 1.00
Importing swarms searches upward from the current working directory for a .env file and loads it into the process environment, so a cloned or untrusted project directory can set provider API base URLs and keys (read by LiteLLM), turn telemetry on or off, or move the workspace. Optional persistent memory (off by default) appends every message, including tool output, to MEMORY.md and re-injects it as a System message in later sessions, keyed only by agent name with no validation or per-user namespace.
C7 Third-party extensions
Minimal 0.23 / 1.00
Third-party code enters mainly through MCP servers the developer configures. Nothing is enabled by default, but there is no version pinning, integrity check or re-approval when a server's tools change, and stdio servers are launched as the same user with a full copy of the process environment, including every API key. Marketplace prompts can be pulled by ID at construction time without verification.
C8 Secrets & sensitive-data protection
Minimal 0.07 / 1.00
Telemetry is on by default and ships each Agent's constructor configuration plus each run's task and output to a vendor endpoint on railway.app. Secret handling on the telemetry, error-logging and model-provider transport paths is not locked down either, and shell and MCP subprocesses inherit every key. Only the MCP manager's own summary and its OAuth token cache are protected.
C9 Audit & traceability
Minimal 0.15 / 1.00
Tool outputs are appended to the in-memory conversation with timestamps, and loguru writes general logs to WORKSPACE_DIR/logs, but individual tool calls are only logged in verbose mode and the conversation is saved only if autosave is turned on. There is no actor attribution, no correlation across sub-agents, and records live in the workspace that the agent's own file tools can modify.
C10 Limits & kill switch
Minimal 0.38 / 1.00
The default Agent runs a single loop. Autonomous mode is bounded by planning attempts (5), total iterations (100) and loops per subtask (20), and shell commands time out after 60 seconds. There is no wall-clock or token/cost budget, user tools have no timeout, and sub-agents created by the model get their own fresh loop budgets with no cap on how many are spawned. Stopping relies on KeyboardInterrupt; background sub-agent tasks are not guaranteed to stop.