C1 Identity & least privilege
Minimal 0.00 / 1.00
Forge runs as the local user and does nothing to narrow that authority. Shell commands start from the user's own shell with the full process environment, so cloud keys, Git tokens and provider API keys present there are available to anything the model runs. There is no separate identity, scoped token or authorization layer in code. If the agent is steered into misuse, it can do whatever the user's account can do.
C2 Approval gates
Minimal 0.25 / 1.00
Out of the box Forge asks for no approval at all: shell commands, file writes and deletions, and web fetches run as soon as the model calls them. An opt-in restricted mode can ask the user before built-in tools run, but even when switched on, the shipped permission rules allow every read, write, command and URL, so the user also has to write their own rules. Commands are matched as plain text patterns, MCP tools and sub-agent calls never pass through the check, and the rules file can be rewritten by the agent's own tools. File edits made through the file tools can be undone; shell commands cannot.
C3 Tool & action scoping
Minimal 0.13 / 1.00
Forge's tools are general purpose: the shell tool takes any command string, the fetch tool takes any URL, and the file tools accept any absolute path on the machine. The only argument checks are that paths are absolute and commands are not empty; there is no workspace containment, host allowlist or block on internal addresses. Each agent has a tool list, but the default agent gets shell, write, remove, fetch, delegation and all MCP tools. A misused tool can therefore act on the whole machine and any reachable host.
C4 Code-execution isolation
Minimal 0.00 / 1.00
Every shell command the model writes runs directly on the host as the user, through the user's own shell, with the full environment. MCP stdio servers are also launched as ordinary host processes. The `--sandbox` flag only creates a separate git worktree and branch; it is not an isolation boundary. Anything the model runs, including repository scripts, can read and change everything the user can, and use every credential in the environment.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Forge reads untrusted content from the web (fetch tool), repository files, command output and MCP tool results, and puts it into the model's context with no marking or special handling. In the same session it holds the user's credentials and can run shell commands, write files and make arbitrary web requests without asking. If injected text takes over the session, it can both send data out and make irreversible changes with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.17 / 1.00
Forge loads several things from the project it is opened in without asking: `.env` files from the working directory and every parent directory (their FORGE_ settings and provider variables feed the configuration), AGENTS.md instructions, and custom agents, skills and commands under `.forge/`, where a project agent can replace the built-in default agent with its own tools and prompt. Only a project `.mcp.json` triggers a trust prompt, remembered per file content. The model can also write AGENTS.md, so injected instructions can persist into later sessions. Opening an untrusted repository can therefore change endpoints, settings and the agent's behaviour before the user does anything.
C7 Third-party extensions
Minimal 0.25 / 1.00
MCP servers are the main third-party extension. The user adds them by command line or URL in a user-scope file or a project `.mcp.json`; nothing is pinned or hash-checked, so a command like `npx some-server` runs whatever is current. A project `.mcp.json` triggers a trust prompt that is remembered per file content and asks again when the file changes, but the prompt shows only the file path, not the commands it will run, and the trust decision does not hold in every configuration. Launched servers are ordinary host processes that inherit the user's full environment.
C8 Secrets & sensitive-data protection
Minimal 0.15 / 1.00
Provider API keys are stored in a plaintext JSON file in the Forge config directory with owner-only permissions, and authorization headers are redacted in debug HTTP logs. Nothing else is masked: tool-call arguments are logged in full, shell commands inherit every secret in the environment, and the model can read the credentials file with its own tools. Release builds send usage telemetry to a third party by default, including the text of prompts, command-line arguments, the working directory and, on errors, the current conversation; the FORGE_TRACKER switch only removes the user-identifying extras.
C9 Audit & traceability
Moderate 0.50 / 1.00
Every tool call, including MCP tools, is logged with its full arguments before it runs, and the conversation, including tool calls and results, is saved to a local database in the Forge config directory after each model request. Sub-agent runs are saved as their own conversations. The record does not say who approved what, sub-agent conversations are not linked to the parent run, and both the database and the log files sit where the agent's own shell and file tools can change or delete them.
C10 Limits & kill switch
Minimal 0.40 / 1.00
Each turn stops after 100 model requests by default, every built-in and MCP tool call is cut off after 300 seconds, and a turn ends after three failures of the same tool. A loop detector only adds a reminder to the model. There is no token or cost budget, sub-agents start their own fresh request budget with no limit on delegation depth or parallel tasks, and a project's own agent files can set a higher per-turn cap. Ctrl+C stops the current operation and the shell child is killed, but background processes the commands started keep running.