# Defense-in-Depth Score: Cherry Studio

**Repo:** https://github.com/CherryHQ/cherry-studio · **Commit:** `50d69b685697a8c3a634bc8b4f19ce3978768423` · **Reviewed:** 2026-10-05
**What it is:** Desktop AI productivity studio with autonomous agents and MCP
**Category:** AI Assistants
**Scored configuration:** Packaged desktop app on first launch with default preferences, including the seeded built-in Cherry Assistant agent (Claude Code runtime, accept-edits permission mode) once the user assigns it a model, with agent browser control on as shipped.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication opt-in

## Score: 2.0 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L0 | L0 | L1 | 0.05 | — | **0.05** | High |
| C2 | Approval gates | L3 | L1 | L1 | L1 | 0.40 | C2-POWERBYPASS | **0.25** | High |
| C3 | Tool & action scoping | L2 | L2 | L1 | L0 | 0.35 | — | **0.35** | High |
| C4 | Code-execution isolation | L0 | L0 | L0 | L0 | 0.00 | — | **0.00** | High |
| C5 | Untrusted input blast radius | L0 | L0 | L0 | L0 | 0.00 | C5-WORSTCASE | **0.00** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L1 | L1 | 0.10 | C6-REPOCONFIG | **0.10** | High |
| C7 | Third-party extensions | L1 | L1 | L0 | L1 | 0.20 | — | **0.20** | Medium |
| C8 | Secrets & sensitive-data protection | L2 | L2 | L2 | L0 | 0.40 | — | **0.40** | High |
| C9 | Audit & traceability | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | Medium |
| C10 | Limits & kill switch | L1 | L1 | L0 | L1 | 0.20 | — | **0.20** | High |


Cherry Studio ships a carefully engineered approval layer for its agents: a per-call card that shows the exact shell command, a central policy registry for its own tools, path-containment checks, and hard blocks on some destructive and global-install commands. Around that layer, the agent runs shell commands directly on the host with the user's full login environment and no sandbox, and tools run by sub-agents, scheduled tasks and chat-channel turns are allowed without asking. Web fetch, browser control (including running page scripts in a persistent browser profile) and task scheduling are auto-approved, so content the agent reads can drive data out and plant follow-up work. Workspace plugin folders and project settings files are loaded without a trust prompt.

## Critical gaps
- Shell commands requested inside a sub-agent, or in scheduled and channel turns, are allowed without approval, so the most powerful action path can skip the gate. (ASI09, ASI02, T10; C2) — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:548-557](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L548-L557); [src/shared/ai/claudecode/toolRegistry.ts:90-95](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/ai/claudecode/toolRegistry.ts#L90-L95)
- Agent-run code executes on the host with no sandbox and the user's full login-shell environment. (ASI05, T11; C4) — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181)
- A hijacked agent can exfiltrate through auto-approved fetch and browser tools and run shell commands through sub-agents or scheduled tasks, with no human involved. (ASI01, T6, LLM01; C5) — [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:548-557](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L548-L557); [src/main/ai/mcp/servers/cherryAutonomyTools.ts:905](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/servers/cherryAutonomyTools.ts#L905)
- Workspace .claude/plugins folders and project/local settings files are loaded without a trust decision. (ASI06, T1; C6) — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:444-459](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L444-L459); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:703-706](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L703-L706)

## Criterion details

### C1 Identity & least privilege — 0.05 (high)

The agent runs as the user with the user's whole login-shell environment: Cherry Studio starts the Claude Code process with every variable from the user's shell (cloud keys, tokens and anything else exported there), and stdio MCP servers get the same environment. A short block-list only stops an agent's own settings from overriding a few model and runtime variables. There is no per-tool credential, and no authorization check sits between a tool call and the user's ambient authority, so a hijacked agent acts with everything the user can reach from a shell, plus any sites signed into the in-app browser.

- **S L0:** The Claude Code subprocess environment is built from the full login-shell environment; no scoped identity exists. — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181) (verified)
  - *To reach the next level:* No per-tool or per-capability credential scoping; the agent inherits every exported shell credential.
- **C L0:** stdio MCP servers also receive the full login-shell environment merged with their own variables. — [src/main/ai/mcp/mcpLaunch.ts:123](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpLaunch.ts#L123); [src/main/ai/mcp/mcpStdioLaunch.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpStdioLaunch.ts#L52-L57) (verified)
  - *To reach the next level:* No tool path passes an authorization check before acting with inherited credentials.
- **D L0:** The default install runs agents with the user's full ambient environment; the block-list only protects runtime variables from agent overrides. — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181); [src/main/ai/runtime/claudeCode/environment.ts:210](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L210) (verified)
  - *To reach the next level:* No minimal default identity; least privilege would require launching the app from a scrubbed environment.
- **B L1:** A hijacked agent reaches the user's files, every inherited credential, and websites signed into the persistent in-app browser profile. — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181); [src/shared/data/preference/preferenceSchemas.ts:607](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/data/preference/preferenceSchemas.ts#L607) (verified)
  - *To reach the next level:* Authority is not limited to one system or project.
- **Cap:** none

### C2 Approval gates — 0.25 (high)

Cherry Studio has a real approval system. Shell commands that need approval appear on a card showing the exact command, Cherry's own tools are classified in one policy registry as auto, required or mode-dependent, and a guard table adds deny and ask rules, such as blocking global package installs and sqlite writes to the app's own database. But approval does not cover everything. Tool calls made inside sub-agents (the sub-agent tool is always available) and in scheduled or chat-channel turns are allowed without asking. Browser actions, including running page scripts, plus web fetch and task scheduling, are auto-approved. The built-in assistant ships in accept-edits mode, and project settings files can add their own allow rules.

- **S L3:** Per-call approval emits the exact tool input to a card that renders the full command, with a policy registry deciding which tools need a human. — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:596-601](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L596-L601); [src/renderer/components/chat/messages/tools/agent/BashTool.tsx:32-35](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/renderer/components/chat/messages/tools/agent/BashTool.tsx#L32-L35); [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84-111](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84-L111) (verified)
  - *To reach the next level:* Approval does not use argument-level allow/deny rules for shell commands, and the approver can return a modified input.
- **C L1:** Sub-agent and headless turns auto-allow ordinary tools, and mutating browser and scheduling tools are marked auto. — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:548-557](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L548-L557); [src/main/ai/toolApproval/browserToolPolicy.ts:19-25](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/browserToolPolicy.ts#L19-L25); [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84-111](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84-L111); [src/shared/ai/claudecode/toolRegistry.ts:90-95](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/ai/claudecode/toolRegistry.ts#L90-L95) (verified)
  - *To reach the next level:* Mutating browser, scheduling and sub-agent paths do not cross the gate.
- **D L1:** The seeded assistant ships in accept-edits mode, and project and local settings sources are loaded, so a workspace settings file can add allow rules. — [src/main/data/db/seeding/seeders/cherryAssistantSeeder.ts:21](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/seeding/seeders/cherryAssistantSeeder.ts#L21); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:703-706](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L703-L706) (verified)
  - *To reach the next level:* A workspace settings file can pre-approve tools; elevated modes are not session- or time-bounded.
- **B L1:** No file checkpointing is enabled, and auto-approved browser actions on signed-in sites cannot be undone. — searched `rg -n enableFileCheckpointing` in `src` → 0 hits (Claude Code file checkpointing is not enabled; fork checkpoints restore conversation state, not files.); [src/main/ai/toolApproval/browserToolPolicy.ts:19-25](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/browserToolPolicy.ts#L19-L25) (verified)
  - *To reach the next level:* No rollback for file or external actions.
- **Cap:** C2-POWERBYPASS — Shell commands requested inside a sub-agent, reachable through the always-enabled Agent tool, are allowed without approval in the default configuration.

### C3 Tool & action scoping — 0.35 (high)

Some tools validate their inputs well. File tools resolve paths through symlinks and ask before touching anything outside the workspace and agent data folder, web fetch refuses addresses that resolve to private or local networks, and guard rules block global installs and writes to the app's own database. But the shell tool takes any command string, reads outside the workspace stay silent by design, and the default tool set includes shell, file writes and a scriptable browser, each of which can be switched off individually.

- **S L2:** Resolved-path containment and a private-address URL check exist, but Bash is a raw command string and out-of-workspace access only asks. — [src/main/ai/runtime/claudeCode/pathContainment.ts:38-59](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/pathContainment.ts#L38-L59); [src/main/ai/runtime/claudeCode/guardRules.ts:257-268](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L257-L268); [src/main/utils/remoteUrlSafety.ts:307](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/utils/remoteUrlSafety.ts#L307); [src/shared/ai/claudecode/toolRegistry.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/ai/claudecode/toolRegistry.ts#L52-L57) (verified)
  - *To reach the next level:* The shell tool has no argument validation and path containment asks rather than denies.
- **C L2:** Built-in file and fetch tools validate; extension and MCP tools get no shared validation layer. — [src/main/ai/runtime/claudeCode/guardRules.ts:257-268](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L257-L268); [src/main/ai/runtime/claudeCode/guardRules.ts:166-175](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L166-L175); [src/main/ai/runtime/claudeCode/guardRules.ts:151-157](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L151-L157) (verified)
  - *To reach the next level:* No shared validation layer wraps extension tools.
- **D L1:** Shell, write and browser-execute tools are on by default and can be disabled per agent. — [src/shared/ai/claudecode/toolRegistry.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/ai/claudecode/toolRegistry.ts#L52-L57); [src/main/ai/mcp/browserTools.ts:21](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/browserTools.ts#L21); [src/shared/data/preference/preferenceSchemas.ts:607](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/data/preference/preferenceSchemas.ts#L607) (verified)
  - *To reach the next level:* No read-only default tool set.
- **B L0:** A misused shell tool reaches the whole machine with the user's environment. — [src/shared/ai/claudecode/toolRegistry.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/ai/claudecode/toolRegistry.ts#L52-L57); [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181) (verified)
  - *To reach the next level:* Reach is not limited to the workspace.
- **Cap:** none

### C4 Code-execution isolation — 0.00 (high)

The default Claude Code agent runtime runs shell commands directly on the host as the user, with no container or OS sandbox, and with the full login-shell environment, so any credential in that environment is visible to executed code. A separate, optional agent runtime uses third-party sandbox packages, but it is not the default and was not reviewed. If agent-run code goes wrong, it has host-level access.

- **S L0:** No sandbox primitive is configured for the Claude Code subprocess. — searched `rg -n -i sandbox` in `src/main/ai/runtime/claudeCode` → 1 hits (The only hit is an unused SandboxSettings type import in types.ts; no sandbox option is passed to the Claude Code subprocess.) (verified)
  - *To reach the next level:* No OS-level or container isolation around agent-executed code.
- **C L0:** No execution path is isolated: shell, scripts and stdio MCP servers all run on the host. — searched `rg -n -i sandbox` in `src/main/ai/runtime/claudeCode` → 1 hits (The only hit is an unused SandboxSettings type import in types.ts; no sandbox option is passed to the Claude Code subprocess.); [src/main/ai/mcp/mcpStdioLaunch.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpStdioLaunch.ts#L52-L57) (verified)
  - *To reach the next level:* No execution path is sandboxed.
- **D L0:** No isolation exists to be on by default in the default runtime. — searched `rg -n -i sandbox` in `src/main/ai/runtime/claudeCode` → 1 hits (The only hit is an unused SandboxSettings type import in types.ts; no sandbox option is passed to the Claude Code subprocess.) (verified)
  - *To reach the next level:* No default-on sandbox.
- **B L0:** Executed code runs host-equivalent with the full inherited environment. — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181) (verified)
  - *To reach the next level:* Execution is not confined to the workspace and credentials are not removed.
- **Cap:** none

### C5 Untrusted input blast radius — 0.00 (high)

Nothing structurally limits what content the agent reads can make it do. Web pages, browser pages, files and MCP results enter the conversation like any other tool output, and fetching URLs and driving the browser are auto-approved, so data can leave without a person seeing it. A hijacked agent can also delegate shell work to a sub-agent, or schedule a task with its own prompt, and both run without approval.

- **S L0:** No taint tracking, quarantine or provenance-based gating exists for untrusted content. — [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84); [src/main/ai/toolApproval/browserToolPolicy.ts:19-25](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/browserToolPolicy.ts#L19-L25) (verified)
  - *To reach the next level:* No capability is disabled or forced through approval after untrusted content is read.
- **C L0:** Tool results from web, browser, files and MCP are not distinguished from other context. — [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:537-542](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L537-L542) (verified)
  - *To reach the next level:* Untrusted sources are not distinguished.
- **D L0:** No such control exists to be on by default. — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:537-542](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L537-L542) (verified)
  - *To reach the next level:* No default-on untrusted-input control.
- **B L0:** Auto-approved fetch and browser tools give an unattended exfiltration channel, and sub-agent and scheduled turns run shell commands without approval. — [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L84); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:548-557](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L548-L557); [src/main/ai/mcp/servers/cherryAutonomyTools.ts:905](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/servers/cherryAutonomyTools.ts#L905) (verified)
  - *To reach the next level:* Exfiltration and irreversible actions are both reachable unattended.
- **Cap:** C5-WORSTCASE — Worst case (B L0): a hijacked agent can leak data and take irreversible actions unattended.
- **Notes:** Chat channels (Telegram, Slack and others) are opt-in; their turns run headless with the same auto-allow behaviour for ordinary tools.

### C6 Memory, context & configuration integrity — 0.10 (high)

Agents keep persistent memory files (persona, user profile and facts) that the model can rewrite through an auto-approved memory tool or file edits, and they are loaded back into the system prompt in every later session. The workspace's instruction files are also loaded automatically. For a user-chosen workspace folder, plugins under its .claude/plugins directory and its project and local settings files are loaded without any trust prompt; plugins can carry hooks and MCP servers.

- **S L0:** Memory files are model-writable and re-injected, and workspace plugin folders and project settings load with no prompt. — [src/main/ai/agents/prompt.ts:102-103](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/agents/prompt.ts#L102-L103); [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:106](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L106); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:444-459](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L444-L459); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:334](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L334) (verified)
  - *To reach the next level:* No validation or approval on memory writes and no workspace-trust decision for repo-supplied plugins or settings.
- **C L0:** No memory store or auto-loaded file path is controlled. — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:215-216](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L215-L216); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:200-206](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L200-L206) (verified)
  - *To reach the next level:* No store or auto-loaded file is gated.
- **D L1:** Memory lives in a per-agent data directory keyed by agent id, but the agent's shell and file tools can reach other agents' directories. — [src/main/ai/agents/prompt.ts:102-103](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/agents/prompt.ts#L102-L103) (verified)
  - *To reach the next level:* Namespace isolation is not enforced against the agent's own tools.
- **B L1:** Poisoned memory or a planted plugin persists across the user's sessions and can trigger tool use. — [src/main/ai/agents/prompt.ts:102-103](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/agents/prompt.ts#L102-L103); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:200-206](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L200-L206) (verified)
  - *To reach the next level:* Persistence is not limited to text output or gated actions.
- **Cap:** C6-REPOCONFIG — A user-selected workspace's .claude/plugins directory and project/local settings files are loaded automatically, which can add hooks, MCP servers and allow rules without an explicit trust decision.

### C7 Third-party extensions — 0.20 (medium)

MCP servers are added by the user from presets or by hand, often as npx commands that fetch the latest package at each launch, with no version pin or integrity check; only managed skills are hashed into an installation baseline. The agent can also ask to install MCP servers and command-line tools, and Cherry routes those requests through per-call approval, and an MCP server the agent registers stays inactive until the user turns it on. Plugins found in the workspace's .claude/plugins folder are loaded with no consent step. Every stdio server runs as the user with the full login-shell environment.

- **S L1:** User-chosen MCP sources launch unpinned (for example npx -y) with no hash or signature check. — [src/shared/data/presets/mcpServers.ts:62-63](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/data/presets/mcpServers.ts#L62-L63); searched `rg -n -i 'sha256|integrity|checksum'` in `src/main/ai/mcp/mcpLaunch.ts src/main/ai/mcp/mcpStdioLaunch.ts src/main/ai/mcp/mcpTransport.ts` → 0 hits (No hash or signature check on launched MCP packages.) (verified)
  - *To reach the next level:* No version pinning or integrity verification.
- **C L1:** Managed skills are hashed into an installation baseline for change detection; MCP servers and workspace plugins are not verified. — [src/main/ai/skills/SkillInstaller.ts:191-203](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/skills/SkillInstaller.ts#L191-L203); searched `rg -n -i 'sha256|integrity|checksum'` in `src/main/ai/mcp/mcpLaunch.ts src/main/ai/mcp/mcpStdioLaunch.ts src/main/ai/mcp/mcpTransport.ts` → 0 hits (No hash or signature check on launched MCP packages.); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:444-459](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L444-L459) (inferred)
  - *To reach the next level:* MCP servers and workspace plugins get no integrity check.
- **D L0:** Workspace plugin folders are loaded silently. — [src/main/ai/runtime/claudeCode/settingsBuilder.ts:444-459](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L444-L459); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:200-206](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L200-L206); [src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:109-111](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/toolApproval/builtinToolPolicyRegistry.ts#L109-L111) (verified)
  - *To reach the next level:* A workspace can add extensions without consent.
- **B L1:** stdio extensions run as separate processes with the full login-shell environment. — [src/main/ai/mcp/mcpLaunch.ts:123](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpLaunch.ts#L123); [src/main/ai/mcp/mcpStdioLaunch.ts:52-57](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpStdioLaunch.ts#L52-L57) (verified)
  - *To reach the next level:* Extension processes do not get a scrubbed environment.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.40 (high)

Cherry Studio redacts secrets in its logs and crash reports. Crash reporting and analytics send nothing until the user accepts the current privacy policy, and channel replies are scrubbed of known secret patterns. Provider API keys are stored as plain JSON in the local database. The agent runs a shell with the user's full environment, so long-lived keys from that environment, and the app's own stored keys, are readable by agent-run code.

- **S L2:** Logger and crash-report paths redact secret patterns; provider keys are stored as plaintext JSON. — [src/main/core/logger/LoggerService.ts:54](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/core/logger/LoggerService.ts#L54); [src/main/services/sentry.ts:70-72](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/services/sentry.ts#L70-L72); [src/main/data/db/schemas/userProvider.ts:62](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/schemas/userProvider.ts#L62) (verified)
  - *To reach the next level:* No encryption at rest or keychain storage for provider keys.
- **C L2:** Logs, crash reports and channel output are redacted; subprocess environments and model-bound tool output are not. — [src/main/core/logger/LoggerService.ts:54](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/core/logger/LoggerService.ts#L54); [src/main/ai/channels/security/OutputSanitizer.ts:66](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/channels/security/OutputSanitizer.ts#L66); [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181) (verified)
  - *To reach the next level:* Subprocess environments and model-bound messages are not protected.
- **D L2:** Crash reporting and analytics require acceptance of the current policy version, which is empty by default. — [src/main/services/sentry.ts:70-72](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/services/sentry.ts#L70-L72); [src/shared/data/preference/preferenceSchemas.ts:625](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/data/preference/preferenceSchemas.ts#L625) (verified)
  - *To reach the next level:* Redaction is not applied to every path, and stored transcripts are not minimised.
- **B L0:** Long-lived keys from the login shell and the app database are reachable by agent subprocesses. — [src/main/ai/runtime/claudeCode/environment.ts:179-181](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/environment.ts#L179-L181); [src/main/data/db/schemas/userProvider.ts:62](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/schemas/userProvider.ts#L62) (verified)
  - *To reach the next level:* Keys are long-lived and broadly reachable.
- **Cap:** none

### C9 Audit & traceability — 0.45 (medium)

Agent conversations, including tool calls and their inputs and results, are stored in the app's local database, and the Claude Code runtime keeps its own session transcripts in Cherry's config directory for a retention period. Detailed tracing exists only in developer mode. Records are local and written by the same process tree the agent runs in, without tamper evidence.

- **S L2:** Agent session messages, including tool parts, are persisted as structured JSON per session. — [src/main/data/db/schemas/agentSessionMessage.ts:19-21](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/schemas/agentSessionMessage.ts#L19-L21); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:337](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L337) (verified)
  - *To reach the next level:* No actor attribution separating agent, sub-agent and approver, or correlation across sub-agents.
- **C L2:** Built-in and MCP tool calls appear in the session transcript; approvals and sub-agent internals are not separately recorded. — [src/main/data/db/schemas/agentSessionMessage.ts:19-21](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/schemas/agentSessionMessage.ts#L19-L21) (inferred)
  - *To reach the next level:* Approvals, denials and sub-agent activity are not recorded as first-class events.
- **D L2:** Records live in app data outside the workspace; detailed tracing is opt-in via developer mode. — [src/main/ai/observability/runtime/NodeTraceService.ts:23-25](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/observability/runtime/NodeTraceService.ts#L23-L25); [src/main/ai/runtime/claudeCode/settingsBuilder.ts:337](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/settingsBuilder.ts#L337) (verified)
  - *To reach the next level:* The agent's own shell can still alter the records.
- **B L1:** Persistence is best-effort; a write failure does not block the action. — [src/main/data/db/schemas/agentSessionMessage.ts:19-21](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/data/db/schemas/agentSessionMessage.ts#L19-L21) (verified)
  - *To reach the next level:* Records are not guaranteed per action.
- **Cap:** none

### C10 Limits & kill switch — 0.20 (high)

The agent runtime is given no turn limit and no spending cap. What exists is a breaker that blocks a shell command repeated five times with identical output, a 60-second default timeout on MCP tool calls, and a 100-call cap on plain chat assistants. Pressing stop closes the session and its Claude Code process, but scheduled tasks created by the agent keep firing.

- **S L1:** A repeated-command breaker and MCP call timeouts exist; there is no iteration or cost cap. — [src/main/ai/runtime/claudeCode/guardRules.ts:186-195](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L186-L195); [src/main/ai/mcp/mcpRequestOptions.ts:18](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/mcpRequestOptions.ts#L18); searched `rg -n 'maxTurns|maxBudgetUsd'` in `src/main/ai` → 0 hits (No turn or spend cap is passed to the agent runtime.) (verified)
  - *To reach the next level:* No step or token/cost cap on agent runs.
- **C L1:** Limits apply to individual tool calls; sub-agents and scheduled runs share no budget. — [src/main/ai/runtime/claudeCode/guardRules.ts:186-195](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/runtime/claudeCode/guardRules.ts#L186-L195); [src/shared/data/types/assistant.ts:114](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/shared/data/types/assistant.ts#L114) (verified)
  - *To reach the next level:* Sub-agents and background tasks do not count against a shared budget.
- **D L0:** Agent sessions are unlimited by default in steps and spend. — searched `rg -n 'maxTurns|maxBudgetUsd'` in `src/main/ai` → 0 hits (No turn or spend cap is passed to the agent runtime.) (verified)
  - *To reach the next level:* No default turn or spend ceiling.
- **B L1:** Stop closes the session, but scheduled jobs the agent created continue to run. — [src/main/ai/agentSession/AgentSessionRuntimeService.ts:899-901](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/agentSession/AgentSessionRuntimeService.ts#L899-L901); [src/main/ai/mcp/servers/cherryAutonomyTools.ts:905](https://github.com/CherryHQ/cherry-studio/blob/50d69b685697a8c3a634bc8b4f19ce3978768423/src/main/ai/mcp/servers/cherryAutonomyTools.ts#L905) (verified)
  - *To reach the next level:* Stopping does not cancel scheduled work, and no spend ceiling exists.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Auto-approved web_fetch and browser tools read arbitrary pages (src/main/ai/toolApproval/builtinToolPolicyRegistry.ts:84; src/main/ai/toolApproval/browserToolPolicy.ts:23) · [B] sensitive data/systems: Agent subprocess inherits the full login-shell environment (src/main/ai/runtime/claudeCode/environment.ts:180) and can read provider keys stored in the local database (src/main/data/db/schemas/userProvider.ts:62) · [C] state change / egress: Host shell, file writes, browser actions and outbound fetches in the same session; sub-agent and headless turns auto-allow ordinary tools (src/main/ai/runtime/claudeCode/settingsBuilder.ts:556) · Same default session? Yes

## Highest-impact improvements
1. Route sub-agent and headless (scheduled/channel) tool calls through the same per-call approval or a strict read-only allowlist instead of auto-allowing them. — C2 C L1→L2, +0.075 before caps (Playbook 5)
2. Run the agent subprocess and stdio MCP servers with a scrubbed environment containing only the variables they need. — C1 S L0→L1, +0.075 before caps (Playbook 4)
3. Require an explicit workspace-trust decision before loading .claude/plugins and project/local settings from a user-selected workspace. — C6 S L0→L1, +0.075 before caps (Playbook 2)
4. Add default turn and spend caps to agent sessions and scheduled runs. — C10 D L0→L2, +0.100 before caps (Playbook 3)
5. Make browser script execution and navigation require approval by default once untrusted content has been read. — C5 S L0→L2, +0.150 before caps (Playbook 1)

## Re-audit log
- No changes.

## Limitations
- Static review of the pinned commit only; nothing was installed, built or run.
- Behaviour of the bundled Claude Agent SDK (how it applies project settings, hooks and its own permission checks before calling Cherry's canUseTool) is inferred from the SDK's documented behaviour, not read in its source.
- The pi and dsh agent runtimes, the dsh sandbox packages (@deepseek-ai/*), mini-apps, remote access/LAN transfer and the knowledge-base pipeline were examined only briefly or not at all; the scored path is the default Claude Code runtime.
- The plain chat assistants (AI SDK runtime) were reviewed only for MCP approval defaults and step caps; no MCP servers are installed for them on a fresh install.
