C1 Identity & least privilege
Minimal 0.00 / 1.00
Maestro runs every agent as the desktop user and hands each one a copy of its entire environment, so the agents inherit every API key, cloud credential, gh login and SSH agent socket the user has. Nothing in Maestro maps actions to a narrower identity or checks authorization per request. A remote-control web server also starts at every launch, listens on all network interfaces over plain HTTP, and accepts any client that presents the URL token, which can then run terminal input and change settings. A hijacked agent or stolen link therefore carries the user's full account authority.
C2 Approval gates
Minimal 0.00 / 1.00
There is no approval step for anything an agent does. Maestro launches Claude Code with its permission prompts disabled, Codex with approvals and sandbox both bypassed, Factory Droid with permissions skipped and Copilot with every tool, path and URL allowed, and the code comments call this a requirement. No approval hook or permission-prompt tool is wired in, so shell commands, file writes, pushes and network calls all run unattended. Changes are not checkpointed, so a bad action can be irreversible.
C3 Tool & action scoping
Minimal 0.05 / 1.00
Maestro does not define or narrow the tools the model uses; it passes through the underlying coding agents with every tool, path and URL enabled. There is no argument validation in Maestro for shell commands, paths or URLs. A per-tab read-only mode exists that asks the underlying CLI to run in plan or read-only mode, which is the only way to reduce what an agent can do, and it is off by default.
C4 Code-execution isolation
Minimal 0.00 / 1.00
Agent commands run directly on the host as the user. Maestro explicitly disables Codex's built-in sandbox with its bypass flag, and it ships no container, VM or OS sandbox of its own. Cue automations can also run shell commands from a project's configuration file straight through the user's shell. Anything an agent or script runs can reach the whole home directory, credentials and the network.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Agents routinely read untrusted content: repository files, web pages, and in Cue and Symphony workflows the bodies of GitHub issues and pull requests written by anyone. Because every agent runs with approvals and sandbox off, a successful prompt injection can both read the user's secrets and send them anywhere, and take irreversible actions such as pushing code or deleting files, with no human involved. The only defence is an optional third-party injection classifier for GitHub inputs that needs an API token and lets everything through on any error.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
Maestro Cue reads a .maestro/cue.yaml file from each agent's project folder and turns it into automations that start agents with arbitrary prompts or run shell commands on startup, on file changes, on a schedule or on GitHub activity. Nothing asks the user to trust that file first, so a cloned repository can ship automations that run as soon as the Cue engine is active. Cue is listed as on by default, although a startup check reads the raw setting and may leave the engine off on a never-configured install. The underlying agents also auto-load their own instruction and memory files; Maestro adds a memory viewer that lets the user inspect and delete Claude memory entries.
C7 Third-party extensions
Minimal 0.17 / 1.00
Maestro has no plugin runtime at this commit (its plugin architecture document describes a folder that is not in the source). Third-party content it loads is the playbook marketplace, fetched from the main branch of a vendor GitHub repository with no version pin or integrity check, including script assets that agents are told to run. MCP servers and skills come from the underlying agents' own configuration and Maestro does not verify them. Anything loaded runs through unsandboxed, full-permission agents as the user.
C8 Secrets & sensitive-data protection
Minimal 0.20 / 1.00
Credentials are not kept away from agents: the full environment, including any API keys and tokens, is copied into every agent process, which the model can read. Maestro redacts secrets when building a debug package and strips IP and email from crash reports, and it keeps the system prompt out of spawn logs. There is no OS keychain use, and Sentry crash reporting is on by default.
C9 Audit & traceability
Minimal 0.30 / 1.00
Maestro shows tool calls live in the UI, but by default those tool entries are discarded when the agent exits, and the main-process file log is off by default. What persists is per-session history entries and session output stored in the app's data folder, which the unsandboxed agents could edit. The detailed per-tool record lives in each underlying agent's own transcript, which Maestro does not own.
C10 Limits & kill switch
Minimal 0.40 / 1.00
Maestro bounds some runs: Cue runs time out after 30 minutes with one run at a time per agent and chains capped at 10 hops, and Auto Run stops a document after three no-progress iterations and kills an agent that has been silent for four hours. Loop mode is unlimited by default and there is no token or cost ceiling. Stopping an agent kills its whole process tree.