What was found and fixed?
The review found malformed MCP requests could terminate the standalone listener, authenticated MCP bodies could be buffered without a limit, some website approvals could expand across a registry boundary, and artifact downloads buffered whole files on the host.
The fixes add safe request handling, a 1 MiB MCP body limit, public/private suffix validation for approval aliases, and streamed artifact downloads. Regression checks cover malformed requests, fixed and chunked bodies, affected domain boundaries, large files and interrupted downloads.
Reviewed runtime revision: 629b569. Read the full dated report for scope and evidence.
What passed?
- 1,223 unit checks and 29 contract checks in the VM follow-up; six local checks skipped. The Linux root credential checks passed separately on the VM and in CI.
- Nine real Linux container integration checks, plus browser/shell image checks.
- 21 network egress probes passed, with no failures or skips.
- Typechecks, build and lint passed. npm reported zero known advisories in the two scanned dependency trees at review time.
Inspect the public CI receipt and container/network receipt. These follow-up receipts apply to ea71e4d, including credential validation, deployment preflight and initialization-retry fixes. OS and Chromium packages were not covered by the npm advisory scans.
Privacy and control have boundaries
You choose the host that stores tasks, workspaces and browser profiles. You choose model access, review detected sensitive actions and can take human control. During acknowledged human control, model screenshot/snapshot tools and ordinary agent actions are blocked.
Remote models still receive submitted context. Native model CLIs retain their own host permissions. Browser profiles are not encrypted by BotHearth, retention is not automatic, and approval detection cannot catch every effect. These checks do not establish that every deployment is secure. A real Debian VM completed public-source research, and acknowledged human control blocked model browser capture. See the VM trial, deployment findings and limitations.
Report a problem privately
Use GitHub’s private vulnerability reporting form with the affected commit, environment, impact and reproduction steps. Do not put tokens, bootstrap links, task databases or unpatched exploit details in public issues. This alpha has no security certification or guaranteed response time.