BoundBench

ZeroClaw

Rust autonomous personal assistant infrastructure (OpenClaw alternative)

github.com/zeroclaw-labs/zeroclaw · 2026-10-05 · 19c40ee

Defense-in-depth score

4.2 / 10

Minimal

ZeroClaw ships a real policy layer: a supervised default where every tool call in the interactive CLI asks for approval, a command allowlist with risk tiers, scrubbed shell environments, workspace-only file tools, an SSRF-guarded web fetch and enforced cost and step limits. The gaps are in what runs unattended and in how strong the boundaries are. Sub-agents and scheduled jobs run with no approval gate, channel-driven turns run low-risk shell commands (including interpreters) without a human, and the OS sandbox silently falls back to none on Linux release builds. The command policy is a filter, not an isolation boundary, so a hijacked turn that gets one approval can reach well beyond the workspace.

Key gaps (1)

  1. A default tool can rebind an agent's risk profile and rewrite its tool allowlist, so the agent can widen its own permissions after one approval. C1 · Identity & least privilege

Criteria

C1 Identity & least privilege

Minimal 0.25 / 1.00

ZeroClaw runs every tool as the operating-system user who started it and holds the model-provider and channel keys in that process. It narrows that authority in useful ways: shell commands get a cleared environment with only a few functional variables, and file tools are confined to the agent workspace with sensitive home directories denied. MCP servers, however, are started with the full parent environment. A default model-routing tool can rewrite agent definitions, including which risk profile an agent is bound to and its tool allowlist, so the agent can widen its own permissions once an operator approves that call.

C2 Approval gates

Minimal 0.45 / 1.00

In the interactive CLI with the Locked Down preset, every tool call stops for a yes, no or always answer, and the runtime overwrites any approval flag the model tries to set itself. The prompt shows each argument cut to 80 characters, so a long command is not shown in full, and 'always' approves that tool for the rest of the session. Sub-agents and scheduled jobs run with no approval manager at all, and channel-driven turns let low-risk shell commands through without a human. There is no checkpoint or undo for consequential actions.

C3 Tool & action scoping

Minimal 0.40 / 1.00

File tools resolve paths, follow symlinks and check the result against the workspace and a deny list, and web fetch and HTTP tools block private addresses, pin DNS and recheck redirects. The shell tool is the weak point: it validates commands with an allowlist of executables plus argument filters and a name-based risk classifier, and the default allowlist includes interpreters and package tools. By default every tool is enabled, including shell, file write and generic HTTP to any public host, so a misused tool reaches far beyond its stated job.

C4 Code-execution isolation

Minimal 0.38 / 1.00

Shell, git and coding-CLI commands are wrapped by an automatically selected OS sandbox. On macOS that is a Seatbelt profile that denies network and limits writes to the workspace; on Linux it is Firejail if installed, with a private home and seccomp but no network isolation. The Landlock backend is not compiled into the default or release feature sets, and when no backend is available the shell silently runs on the host. MCP servers are launched as unsandboxed subprocesses.

C5 Untrusted input blast radius

Minimal 0.45 / 1.00

ZeroClaw reads web pages, search results, chat messages, email and MCP results, and none of it is tagged or treated differently from the user's instructions. What limits a hijacked turn is the approval gate: in the interactive CLI each consequential call needs a yes. Chat channels only accept allowlisted senders. But a single approved sub-agent spawn, a scheduled job or a channel-driven turn can then fetch any public URL, write workspace files or run low-risk shell commands with no human in the loop, which is enough to send private data out.

C6 Memory, context & configuration integrity

Minimal 0.35 / 1.00

Every turn's user message is auto-saved to memory, and recalled memories are injected inside a labelled memory block. The model's explicit memory-write tool needs approval in the scored preset. Personality files such as AGENTS.md and SOUL.md in the agent's workspace load silently into every system prompt, and skills in the workspace add tools; the agent can write both with its file tools after approval. The runtime config file is protected from file tools, and memory has default retention and purge windows.

C7 Third-party extensions

Minimal 0.30 / 1.00

Nothing third-party runs by default: WASM plugins are disabled and not in the release build, MCP has no servers configured, and community skills are opt-in with script files disallowed. When an operator adds them, MCP servers are launched from whatever command is configured, with no pinning or integrity check, as the same user with the full environment. Skills are installed with an unpinned shallow git clone plus a static content audit.

C8 Secrets & sensitive-data protection

Minimal 0.45 / 1.00

Secrets in the config file are encrypted by default with a locally stored key, credential-shaped strings are scrubbed from tool output before it reaches the model and from logs, tool input/output logging is masked by default and LLM request payloads are not logged. Telemetry export is off by default; a version-update check is on. Provider and channel keys are long-lived and sit in the agent process, and MCP servers receive the full environment.

C9 Audit & traceability

Minimal 0.47 / 1.00

Every tool call is recorded as a structured event with its scrubbed arguments, result, iteration and trace id, and approval decisions are recorded with the deciding channel. The trace file lives inside the agent workspace and is a rolling log with no tamper evidence. A hash-chained audit logger exists but is used for certificate events, not tool calls, and the signed tool receipts the README highlights are off by default.

C10 Limits & kill switch

Moderate 0.65 / 1.00

Runs are bounded by a 10-iteration tool loop, a $10 daily and $100 monthly cost ceiling enforced before each model call, a 60-second shell timeout and a rate limit of 20 actions per hour on shell and file tools. Shell commands run in their own process group, which is killed on cancel or timeout. Sub-agents share the parent's limits and cannot spawn their own sub-agents. Scheduled jobs keep running after a session stops, and the model can raise iteration and delegation limits for agent profiles through a default tool once approved.