Security
Darce runs commands on your machine, so safety is the product, not a feature. Here's how it works and how to report a problem.
Report a vulnerability
Please report privately through GitHub's private vulnerability reporting, not a public issue. Include what an attacker controls (a repository you clone, a web page Darce reads, a model's output), what they can make Darce do, and steps to reproduce. You'll get a reply within a few days. Fixes ship as a new npm version, with credit in the changelog if you'd like it.
How Darce limits what an agent can do
- Every command is scored before it runs. Read-only commands run. Changes
/undocan reverse run in auto mode. Anything that reaches outside your project or machine (migrations, deploys, pushes, network writes, deleting outside the project) waits for your approval, with the reason shown. See safety and approvals. - Scripts get a second look. Before running a script with an innocent name, Darce reads it and checks whether it reaches outside your machine.
- Web content raises caution. After Darce reads a web page, shell commands ask first, because a page can try to instruct the agent.
- Plan mode is read-only for when you only want analysis.
Undo, and its limits
Darce snapshots your project before every step, including what shell commands changed, using private git refs that never touch your branch, index or stash. It can't reverse effects outside your machine, which is why those always ask first. Details: how undo works.
Secrets
- Secrets Darce recognises in command output (API keys, tokens, private keys) are redacted before anything is sent to a model.
- Environment variables that look like secrets (keys, tokens, passwords, database URLs) are withheld from the commands Darce runs unless you allow them.
- Your API key is stored in
~/.darcercwith permissions only you can read. A project's own config can't set keys, endpoints or approval modes.
Local only
The /brain view listens on 127.0.0.1, every request needs a random token, and files that look like they hold secrets are never shown. The CLI sends no telemetry.
The hosted service
Requests to models go through api.darce.dev, which checks your plan and forwards them; it doesn't store prompt or file content. Passwords are hashed with bcrypt. Payments are handled by Stripe. More in the privacy policy.