# Defense-in-Depth Score: ZeroClaw

**Repo:** https://github.com/zeroclaw-labs/zeroclaw · **Commit:** `19c40eea3ec0926f5938f299a9007baaf9a9b09c` · **Reviewed:** 2026-10-05
**What it is:** Rust autonomous personal assistant infrastructure (OpenClaw alternative)
**Category:** AI Assistants
**Scored configuration:** Release (dist feature set) binary configured with 'zeroclaw quickstart' accepting the pre-selected Locked Down risk preset, default runtime/tool/sandbox settings, used through the interactive 'zeroclaw agent' CLI; channel/daemon (non-interactive) mode footnoted.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions opt-in · sub agents yes · external communication yes

## Score: 4.2 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L1 | L1 | L2 | L1 | 0.30 | C1-SELFESC | **0.25** | High |
| C2 | Approval gates | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |
| C3 | Tool & action scoping | L2 | L2 | L1 | L1 | 0.40 | — | **0.40** | High |
| C4 | Code-execution isolation | L2 | L1 | L2 | L1 | 0.38 | — | **0.38** | High |
| C5 | Untrusted input blast radius | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |
| C6 | Memory, context & configuration integrity | L1 | L1 | L2 | L2 | 0.35 | — | **0.35** | Medium |
| C7 | Third-party extensions | L1 | L1 | L2 | L1 | 0.30 | — | **0.30** | High |
| C8 | Secrets & sensitive-data protection | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |
| C9 | Audit & traceability | L2 | L3 | L1 | L1 | 0.47 | — | **0.47** | High |
| C10 | Limits & kill switch | L3 | L3 | L2 | L2 | 0.65 | — | **0.65** | High |


ZeroClaw ships a real policy layer: a supervised default where every tool call in the interactive CLI asks for approval, a command allowlist with risk tiers, scrubbed shell environments, workspace-only file tools, an SSRF-guarded web fetch and enforced cost and step limits. The gaps are in what runs unattended and in how strong the boundaries are. Sub-agents and scheduled jobs run with no approval gate, channel-driven turns run low-risk shell commands (including interpreters) without a human, and the OS sandbox silently falls back to none on Linux release builds. The command policy is a filter, not an isolation boundary, so a hijacked turn that gets one approval can reach well beyond the workspace.

## Critical gaps
- A default tool can rebind an agent's risk profile and rewrite its tool allowlist, so the agent can widen its own permissions after one approval. (ASI03, T3; C1) — [crates/zeroclaw-tools/src/model_routing_config.rs:1056-1060](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/model_routing_config.rs#L1056-L1060); [crates/zeroclaw-tools/src/model_routing_config.rs:1013-1022](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/model_routing_config.rs#L1013-L1022); [crates/zeroclaw-runtime/src/tools/mod.rs:1427-1430](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L1427-L1430)

## Criterion details

### C1 Identity & least privilege — 0.25 (high)

ZeroClaw runs every tool as the operating-system user who started it and holds the model-provider and channel keys in that process. It narrows that authority in useful ways: shell commands get a cleared environment with only a few functional variables, and file tools are confined to the agent workspace with sensitive home directories denied. MCP servers, however, are started with the full parent environment. A default model-routing tool can rewrite agent definitions, including which risk profile an agent is bound to and its tool allowlist, so the agent can widen its own permissions once an operator approves that call.

- **S L1:** Ambient OS-user authority with long-lived provider keys in process; the shell environment is cleared and rebuilt from a small allowlist, which narrows what spawned commands inherit. — [crates/zeroclaw-runtime/src/tools/shell.rs:305](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/shell.rs#L305); [crates/zeroclaw-runtime/src/tools/shell_env.rs:11-13](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/shell_env.rs#L11-L13) (verified)
  - *To reach the next level:* No per-tool or per-capability credentials; every tool acts with the same user identity.
- **C L1:** The shell path is scrubbed, but MCP stdio servers are spawned with the parent environment plus their configured variables. — [crates/zeroclaw-runtime/src/tools/shell.rs:305](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/shell.rs#L305); [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* MCP servers and other subprocess paths do not pass through the same environment narrowing.
- **D L2:** The default profile is supervised and workspace-only with home-directory secrets denied; widening is an operator config change. — [crates/zeroclaw-config/src/schema.rs:14600-14606](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L14600-L14606); [crates/zeroclaw-config/src/policy.rs:480-500](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L480-L500); [crates/zeroclaw-tools/src/model_routing_config.rs:1056-1060](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/model_routing_config.rs#L1056-L1060) (verified)
  - *To reach the next level:* Write and exec are on by default rather than requiring explicit elevation, and the model can rebind its own risk profile through a default tool.
- **B L1:** If authorization fails, the agent acts with the user's account: any file the user can reach, network egress, connected chat accounts and provider keys. — [crates/zeroclaw-runtime/src/tools/mod.rs:1427-1430](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L1427-L1430); [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* Credentials are long-lived and broad; nothing scopes a hijacked agent to one system.
- **Cap:** C1-SELFESC — The default model_routing_config tool can rebind an agent to a different risk profile and rewrite that profile's tool allowlist, letting the agent modify its own permissions (behind one approval).

### C2 Approval gates — 0.45 (high)

In the interactive CLI with the Locked Down preset, every tool call stops for a yes, no or always answer, and the runtime overwrites any approval flag the model tries to set itself. The prompt shows each argument cut to 80 characters, so a long command is not shown in full, and 'always' approves that tool for the rest of the session. Sub-agents and scheduled jobs run with no approval manager at all, and channel-driven turns let low-risk shell commands through without a human. There is no checkpoint or undo for consequential actions.

- **S L2:** Per-call approval with yes/no/always/replace outcomes, but the CLI renders each argument truncated to 80 characters rather than the exact full call. — [crates/zeroclaw-runtime/src/approval/mod.rs:438-447](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L438-L447); [crates/zeroclaw-runtime/src/approval/mod.rs:368-372](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L368-L372); [crates/zeroclaw-runtime/src/agent/turn/call_prep.rs:229](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/call_prep.rs#L229) (verified)
  - *To reach the next level:* The approver does not see the complete command or diff, and an 'always' answer approves the whole tool for the session.
- **C L2:** All built-in tools prompt in interactive runs, but sub-agent and cron runs get no approval manager (the gate defaults to not required), and non-interactive turns exempt shell from the prompt. — [crates/zeroclaw-runtime/src/agent/loop_.rs:382-394](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/loop_.rs#L382-L394); [crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs:29-32](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs#L29-L32); [crates/zeroclaw-runtime/src/approval/mod.rs:256-261](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L256-L261); [crates/zeroclaw-runtime/src/cron/scheduler.rs:1166-1182](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/cron/scheduler.rs#L1166-L1182) (verified)
  - *To reach the next level:* Sub-agents, scheduled jobs and channel-driven shell calls do not traverse the human gate; auto-run shell commands are not a verified read-only set.
- **D L2:** Approval is on by default; the operator can switch presets, add auto_approve entries or set level=full in config without a warning at run time. — [crates/zeroclaw-config/src/presets.rs:72-92](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/presets.rs#L72-L92); [crates/zeroclaw-runtime/src/approval/mod.rs:274-275](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L274-L275) (verified)
  - *To reach the next level:* Disabling approval is a silent config change rather than an explicit, loudly named operator flag.
- **B L1:** Wrongly approved or unattended calls can push code, send HTTP requests to any public host, message through channels or delete workspace files with no checkpoint or rollback. — [crates/zeroclaw-config/src/schema.rs:8743-8748](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8743-L8748); [crates/zeroclaw-config/src/policy.rs:407-431](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L407-L431) (verified)
  - *To reach the next level:* No checkpoints, previews or dry-runs for consequential actions.
- **Cap:** none

### C3 Tool & action scoping — 0.40 (high)

File tools resolve paths, follow symlinks and check the result against the workspace and a deny list, and web fetch and HTTP tools block private addresses, pin DNS and recheck redirects. The shell tool is the weak point: it validates commands with an allowlist of executables plus argument filters and a name-based risk classifier, and the default allowlist includes interpreters and package tools. By default every tool is enabled, including shell, file write and generic HTTP to any public host, so a misused tool reaches far beyond its stated job.

- **S L2:** Resolved-path containment for file tools and an SSRF-guarded fetch, but the shell is validated by an executable allowlist and argument denylist that interpreters can escape. — [crates/zeroclaw-tools/src/file_write.rs:244](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/file_write.rs#L244); [crates/zeroclaw-tools/src/web_fetch.rs:160-198](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/web_fetch.rs#L160-L198); [crates/zeroclaw-config/src/policy.rs:3628-3630](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L3628-L3630); [crates/zeroclaw-config/src/policy.rs:407-431](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L407-L431) (verified)
  - *To reach the next level:* Shell validation is a filter over a general executor; narrow tools do not replace the shell and interpreter commands.
- **C L2:** Built-in file and search tools are wrapped in path guards and rate limits; MCP tools are not covered by the same argument validation. — [crates/zeroclaw-runtime/src/tools/mod.rs:1331-1341](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L1331-L1341); [crates/zeroclaw-tools/src/file_write.rs:244](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/file_write.rs#L244) (verified)
  - *To reach the next level:* Extension tools are not wrapped by a shared validation layer.
- **D L1:** Shell, file write/edit, web fetch and generic HTTP to any public host are enabled by default and can be individually excluded. — [crates/zeroclaw-config/src/schema.rs:8743-8748](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8743-L8748); [crates/zeroclaw-config/src/schema.rs:8892-8896](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8892-L8896); [crates/zeroclaw-runtime/src/tools/mod.rs:1331-1341](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L1331-L1341) (verified)
  - *To reach the next level:* The default tool set includes write, exec and network tools rather than a read-only set.
- **B L1:** A misused shell or HTTP tool reaches any public host and, through allowlisted interpreters, the whole user account despite workspace-scoped file tools. — [crates/zeroclaw-config/src/policy.rs:407-431](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L407-L431); [crates/zeroclaw-config/src/schema.rs:8743-8748](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8743-L8748) (verified)
  - *To reach the next level:* Tools are not bounded to the workspace or to quantities once the shell's interpreter commands are used.
- **Cap:** none

### C4 Code-execution isolation — 0.38 (high)

Shell, git and coding-CLI commands are wrapped by an automatically selected OS sandbox. On macOS that is a Seatbelt profile that denies network and limits writes to the workspace; on Linux it is Firejail if installed, with a private home and seccomp but no network isolation. The Landlock backend is not compiled into the default or release feature sets, and when no backend is available the shell silently runs on the host. MCP servers are launched as unsandboxed subprocesses.

- **S L2:** Auto-detected Firejail (private home, seccomp, dropped capabilities, no network isolation) or Seatbelt; on Linux release builds without Firejail no isolation applies. — [crates/zeroclaw-runtime/src/security/detect.rs:208-246](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/detect.rs#L208-L246); [crates/zeroclaw-runtime/src/security/firejail.rs:161-171](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/firejail.rs#L161-L171); [Cargo.toml:250-257](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/Cargo.toml#L250-L257) (verified)
  - *To reach the next level:* The common Linux path lacks a hardened sandbox with network denied and workspace-only writes.
- **C L1:** The shell tool and git tool share the runtime sandbox; MCP stdio servers are spawned directly on the host. — [crates/zeroclaw-runtime/src/tools/mod.rs:727-750](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L727-L750); [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* MCP servers and other spawned processes are not sandboxed.
- **D L2:** The sandbox is on by default (auto) but falls back to no sandbox when no backend is available, logged only at info level. — [crates/zeroclaw-config/src/schema.rs:19730-19735](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L19730-L19735); [crates/zeroclaw-runtime/src/security/detect.rs:173-179](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/detect.rs#L173-L179) (verified)
  - *To reach the next level:* No fail-closed behaviour when the sandbox is unavailable.
- **B L1:** With no backend or after escape, commands run as the user with full network; Seatbelt also allows reading home dotfiles. — [crates/zeroclaw-runtime/src/security/detect.rs:173-179](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/detect.rs#L173-L179); [crates/zeroclaw-runtime/src/security/seatbelt.rs:340-343](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/seatbelt.rs#L340-L343) (verified)
  - *To reach the next level:* Execution is not confined to the workspace with egress off.
- **Cap:** none

### C5 Untrusted input blast radius — 0.45 (high)

ZeroClaw reads web pages, search results, chat messages, email and MCP results, and none of it is tagged or treated differently from the user's instructions. What limits a hijacked turn is the approval gate: in the interactive CLI each consequential call needs a yes. Chat channels only accept allowlisted senders. But a single approved sub-agent spawn, a scheduled job or a channel-driven turn can then fetch any public URL, write workspace files or run low-risk shell commands with no human in the loop, which is enough to send private data out.

- **S L2:** Consequential tools need approval in the interactive default, but nothing tracks untrusted content, and egress tools run unattended in sub-agent, cron and channel-driven turns. — [crates/zeroclaw-runtime/src/approval/mod.rs:274-275](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L274-L275); [crates/zeroclaw-runtime/src/agent/loop_.rs:382-394](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/loop_.rs#L382-L394); [crates/zeroclaw-runtime/src/approval/mod.rs:256-261](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L256-L261) (verified)
  - *To reach the next level:* No Rule-of-Two enforcement tied to untrusted content entering the session.
- **C L2:** Chat channels admit only allowlisted senders, but tool results, fetched pages and MCP outputs enter context with the same standing as user text. — [crates/zeroclaw-channels/src/allowlist.rs:42-45](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-channels/src/allowlist.rs#L42-L45); [crates/zeroclaw-runtime/src/agent/tool_execution.rs:398](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/tool_execution.rs#L398) (verified)
  - *To reach the next level:* Tool results, tool descriptions and sub-agent output are not distinguished from principal instructions.
- **D L2:** The approval-based limit is on in the scored preset; operators can drop it by changing preset or auto_approve without warning. — [crates/zeroclaw-config/src/presets.rs:72-92](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/presets.rs#L72-L92); [crates/zeroclaw-config/src/schema.rs:13750-13768](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13750-L13768) (verified)
  - *To reach the next level:* Disabling the limit is not explicit and warned.
- **B L1:** A hijacked sub-agent, cron or channel turn can exfiltrate workspace data and memory through web_fetch or http_request unattended; irreversible actions mostly still need approval. — [crates/zeroclaw-runtime/src/agent/loop_.rs:382-394](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/loop_.rs#L382-L394); [crates/zeroclaw-config/src/schema.rs:8743-8748](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8743-L8748); [crates/zeroclaw-runtime/src/approval/mod.rs:256-261](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L256-L261) (verified)
  - *To reach the next level:* Egress from sessions that read untrusted content is not blocked or forced through approval on every path.
- **Cap:** none

### C6 Memory, context & configuration integrity — 0.35 (medium)

Every turn's user message is auto-saved to memory, and recalled memories are injected inside a labelled memory block. The model's explicit memory-write tool needs approval in the scored preset. Personality files such as AGENTS.md and SOUL.md in the agent's workspace load silently into every system prompt, and skills in the workspace add tools; the agent can write both with its file tools after approval. The runtime config file is protected from file tools, and memory has default retention and purge windows.

- **S L1:** Memory writes are logged but not validated; workspace instruction files load silently as system-prompt context. — [crates/zeroclaw-runtime/src/agent/agent.rs:1813-1822](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/agent.rs#L1813-L1822); [crates/zeroclaw-runtime/src/agent/system_prompt.rs:22-23](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/system_prompt.rs#L22-L23) (verified)
  - *To reach the next level:* Memory entries are not provenance-tagged and instruction or skill files are not gated by a trust decision.
- **C L1:** The runtime config is protected from file tools, but memory, instruction files and workspace skills are not controlled. — [crates/zeroclaw-config/src/policy.rs:4370-4379](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/policy.rs#L4370-L4379); [crates/zeroclaw-runtime/src/agent/system_prompt.rs:22-23](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/system_prompt.rs#L22-L23) (verified)
  - *To reach the next level:* Instruction files and skill directories are not covered by the same protection.
- **D L2:** Recall is scoped per session scope in the injection pipeline, with default retention and purge windows. — [crates/zeroclaw-runtime/src/agent/memory_inject.rs:287-289](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/memory_inject.rs#L287-L289); [crates/zeroclaw-config/src/schema.rs:13198-13207](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13198-L13207) (inferred)
  - *To reach the next level:* Namespace isolation is not shown to be enforced against model writes to other scopes.
- **B L2:** Poisoned memory or instruction files persist across sessions but in the scored preset only influence text and gated actions. — [crates/zeroclaw-runtime/src/tools/mod.rs:1401](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/mod.rs#L1401); [crates/zeroclaw-runtime/src/approval/mod.rs:274-275](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/approval/mod.rs#L274-L275) (verified)
  - *To reach the next level:* Persistent context is not reviewed before use and has no rollback.
- **Cap:** none

### C7 Third-party extensions — 0.30 (high)

Nothing third-party runs by default: WASM plugins are disabled and not in the release build, MCP has no servers configured, and community skills are opt-in with script files disallowed. When an operator adds them, MCP servers are launched from whatever command is configured, with no pinning or integrity check, as the same user with the full environment. Skills are installed with an unpinned shallow git clone plus a static content audit.

- **S L1:** Operator-chosen MCP commands and skill repositories, fetched unpinned. — [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621); [crates/zeroclaw-runtime/src/skills/mod.rs:2826](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/skills/mod.rs#L2826) (verified)
  - *To reach the next level:* No version pinning or integrity check for MCP servers or skill sources.
- **C L1:** Skill installs get a static audit; MCP servers get no verification. — [crates/zeroclaw-runtime/src/skills/mod.rs:2826](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/skills/mod.rs#L2826); [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* Verification does not cover MCP servers.
- **D L2:** Plugins are off and no MCP servers are configured by default, but skills placed in the agent workspace are loaded without an install step showing what will run. — [crates/zeroclaw-config/src/schema.rs:9884-9890](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L9884-L9890); [crates/zeroclaw-config/src/schema.rs:5879-5881](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L5879-L5881); [crates/zeroclaw-config/src/schema.rs:6952-6964](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L6952-L6964) (verified)
  - *To reach the next level:* Adding an extension does not always show the exact package, command and permissions.
- **B L1:** An MCP server runs as a separate process with the user's identity and full environment. — [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* No per-extension sandbox or scrubbed environment.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.45 (high)

Secrets in the config file are encrypted by default with a locally stored key, credential-shaped strings are scrubbed from tool output before it reaches the model and from logs, tool input/output logging is masked by default and LLM request payloads are not logged. Telemetry export is off by default; a version-update check is on. Provider and channel keys are long-lived and sit in the agent process, and MCP servers receive the full environment.

- **S L2:** Encrypted-at-rest config secrets with a local key file plus pattern-based scrubbing of model-visible tool output and logs. — [crates/zeroclaw-config/src/secrets.rs:3-5](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/secrets.rs#L3-L5); [crates/zeroclaw-config/src/schema.rs:8521-8523](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8521-L8523); [crates/zeroclaw-runtime/src/agent/tool_execution.rs:398](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/tool_execution.rs#L398) (verified)
  - *To reach the next level:* Secrets are not held in an OS keychain or secret manager by default.
- **C L2:** Logs, traces and model-bound tool output are scrubbed and the shell environment is cleared, but MCP subprocess environments are not. — [crates/zeroclaw-runtime/src/agent/tool_execution.rs:398](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/tool_execution.rs#L398); [crates/zeroclaw-config/src/schema.rs:13627-13633](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13627-L13633); [crates/zeroclaw-tools/src/mcp_transport.rs:619-621](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/mcp_transport.rs#L619-L621) (verified)
  - *To reach the next level:* Not every path is covered: MCP subprocesses inherit the full environment.
- **D L2:** Observability export is off, tool I/O logging is masked and payload logging off by default; the masking mode is operator-configurable. — [crates/zeroclaw-config/src/schema.rs:13560-13563](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13560-L13563); [crates/zeroclaw-config/src/schema.rs:13627-13633](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13627-L13633); [crates/zeroclaw-config/src/schema.rs:7995](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L7995) (verified)
  - *To reach the next level:* Masking can be turned off through configuration.
- **B L1:** Long-lived, account-level provider and channel keys are held by the process. — [crates/zeroclaw-config/src/schema.rs:8521-8523](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L8521-L8523) (verified)
  - *To reach the next level:* Keys are not short-lived or scoped per task.
- **Cap:** none

### C9 Audit & traceability — 0.47 (high)

Every tool call is recorded as a structured event with its scrubbed arguments, result, iteration and trace id, and approval decisions are recorded with the deciding channel. The trace file lives inside the agent workspace and is a rolling log with no tamper evidence. A hash-chained audit logger exists but is used for certificate events, not tool calls, and the signed tool receipts the README highlights are off by default.

- **S L2:** Structured tool_call_start/tool_call_result records with arguments, iteration and trace id. — [crates/zeroclaw-runtime/src/agent/turn/call_prep.rs:336-351](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/call_prep.rs#L336-L351); [crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs:139-140](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs#L139-L140) (verified)
  - *To reach the next level:* No tamper-evident storage or full principal/approver attribution on tool records.
- **C L3:** All tool calls, including MCP tools and sub-agent turns, go through the same preparation and logging path, and approvals and denials are logged. — [crates/zeroclaw-runtime/src/agent/turn/call_prep.rs:336-351](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/call_prep.rs#L336-L351); [crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs:139-140](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/approval_gate.rs#L139-L140) (verified)
  - *To reach the next level:* Configuration changes, memory writes and credential use are not recorded in the same trail.
- **D L1:** Persistence is on by default but the runtime trace resolves inside the agent workspace. — [crates/zeroclaw-config/src/schema.rs:13589-13595](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L13589-L13595); [crates/zeroclaw-log/src/config.rs:204-213](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-log/src/config.rs#L204-L213) (verified)
  - *To reach the next level:* The record is stored where the agent's own tools can reach it.
- **B L1:** A rolling, best-effort trace; the hash-chained logger and receipts are not used for tool calls by default. — [crates/zeroclaw-runtime/src/security/audit.rs:517](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/security/audit.rs#L517); [crates/zeroclaw-config/src/schema.rs:6703-6707](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L6703-L6707) (verified)
  - *To reach the next level:* Records are not durable per action and logging failure does not block actions.
- **Cap:** none

### C10 Limits & kill switch — 0.65 (high)

Runs are bounded by a 10-iteration tool loop, a $10 daily and $100 monthly cost ceiling enforced before each model call, a 60-second shell timeout and a rate limit of 20 actions per hour on shell and file tools. Shell commands run in their own process group, which is killed on cancel or timeout. Sub-agents share the parent's limits and cannot spawn their own sub-agents. Scheduled jobs keep running after a session stops, and the model can raise iteration and delegation limits for agent profiles through a default tool once approved.

- **S L3:** Iteration cap, enforced cost ceilings, a 120-second default model-call timeout, per-command timeouts and per-hour action rate limits, with process-group kill on cancel. — [crates/zeroclaw-runtime/src/agent/turn/mod.rs:209](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/mod.rs#L209); [crates/zeroclaw-runtime/src/agent/turn/provider_call.rs:187-219](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/provider_call.rs#L187-L219); [crates/zeroclaw-config/src/schema.rs:14723-14732](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L14723-L14732); [crates/zeroclaw-runtime/src/tools/shell.rs:339-344](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/shell.rs#L339-L344); [crates/zeroclaw-providers/src/lib.rs:853](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-providers/src/lib.rs#L853) (verified)
  - *To reach the next level:* In-flight model and tool calls are not all shown to be cancelled by the halt.
- **C L3:** Sub-agents inherit the parent policy and budget scope and are capped at depth one. — [crates/zeroclaw-runtime/src/tools/spawn_subagent.rs:151](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/tools/spawn_subagent.rs#L151); [crates/zeroclaw-runtime/src/agent/turn/provider_call.rs:187-219](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/agent/turn/provider_call.rs#L187-L219) (verified)
  - *To reach the next level:* Concurrency of sub-agents and background jobs is not capped against the same budget.
- **D L2:** Sensible defaults that operators can change; the model-routing tool can raise per-agent iteration and depth limits. — [crates/zeroclaw-config/src/schema.rs:14723-14732](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L14723-L14732); [crates/zeroclaw-config/src/schema.rs:7685-7693](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L7685-L7693); [crates/zeroclaw-tools/src/model_routing_config.rs:1013-1022](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-tools/src/model_routing_config.rs#L1013-L1022) (verified)
  - *To reach the next level:* The model can raise its limits through a default tool.
- **B L2:** Moderate ceilings; stopping a session leaves scheduled cron jobs running. — [crates/zeroclaw-runtime/src/cron/scheduler.rs:1166-1182](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-runtime/src/cron/scheduler.rs#L1166-L1182); [crates/zeroclaw-config/src/schema.rs:7452-7458](https://github.com/zeroclaw-labs/zeroclaw/blob/19c40eea3ec0926f5938f299a9007baaf9a9b09c/crates/zeroclaw-config/src/schema.rs#L7452-L7458) (verified)
  - *To reach the next level:* Scheduled work continues after a stop.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: web_fetch and web search results, chat/email channel messages, MCP results (crates/zeroclaw-tools/src/web_fetch.rs:160) · [B] sensitive data/systems: workspace files and memory via file_read/memory_recall (crates/zeroclaw-tools/src/file_write.rs:244, crates/zeroclaw-runtime/src/tools/mod.rs:1401) · [C] state change / egress: http_request/web_fetch to any public host, shell, file write (crates/zeroclaw-config/src/schema.rs:8743) · Same default session? Yes

## Highest-impact improvements
1. Give sub-agent and cron runs a fail-closed non-interactive approval manager instead of none. — C2 C L2→L3, +0.075 before caps (Playbook 5)
2. Show the full, untruncated command and arguments in the CLI approval prompt. — C2 S L2→L3, +0.075 before caps (Playbook 5)
3. Exclude risk-profile and agent-binding changes from the model_routing_config tool, keeping them operator-only. — C1 S L1→L2, +0.075 before caps (Playbook 4)
4. Ship Landlock in release builds and fail closed when no sandbox backend is available. — C4 D L2→L3, +0.050 before caps (Playbook 3)
5. Write the runtime trace outside the agent workspace. — C9 D L1→L2, +0.050 before caps

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- The quickstart requires an explicit risk-preset choice; the scored configuration uses the CLI picker's pre-selected Locked Down preset. The Balanced preset (described as recommended) allows any non-high-risk command, and YOLO disables approvals and the sandbox.
- Channel/daemon (non-interactive) mode was reviewed for the approval path only; its channel adapters, the gateway web UI, hardware/peripheral tools, SOP engine and WASM plugin runtime were not reviewed in depth.
- Sandbox behaviour was scored from source for the release feature set; platform-specific behaviour (macOS Seatbelt vs Linux Firejail/none) varies and was not run.
- C6 D is inferred from the memory injection pipeline and not traced through every memory backend.
- The README describes cryptographic tool receipts on every action; in code they are off by default (schema.rs:6703).
- No text aimed at AI reviewers was found in README, AGENTS.md or CLAUDE.md.
