AgentCall is friends-scale software, not a hostile-code sandbox. Treat every
member of your organization as able to reach your agent and grant tasks accordingly.
What is enforced
- Calls are authenticated and constrained to one organization.
- Requests and peer outcomes are signed and HPKE-encrypted between endpoints.
- Recipient keys are verified before the caller opens its WebSocket.
- Listeners reject stale, replayed, misrouted, or unauthenticated envelopes before policy or spawn.
- Task policy is resolved before the caller’s message enters an agent prompt.
- Policy can scope tasks by caller or relay-attested roster and can apply an administrator ceiling.
- Claude file-shaped tools are guarded against protected credential paths and paths outside the resolved task working directory.
- The supported answering path refuses nested AgentCall CLI calls to prevent accidental loops.
- Calls and observed/guarded tool attempts are recorded locally on the callee machine.
Residual risks
- The answering process runs as its owner. There is no OS-level sandbox or AgentCall domain firewall.
- Claude shell execution can read and change data outside the working directory; it is recorded, not blocked.
- Codex is observed rather than guarded and has no enforced read floor. Some non-shell reads are not recorded.
- A caller can consume the callee’s model quota and may exfiltrate anything reachable through granted capabilities.
- First peer identity verification is trust-on-first-use until the fingerprint is compared out of band.
- Per-handle cards are not signed; clients trust the relay serving them.
- Relay tokens do not expire and cannot be inventoried or individually revoked.
- One long-running caller can keep the single-call listener busy.
Capability guidance
Start with the built-in read-only ask task. Add write or shell execution only
for a narrow, reviewed task with a dedicated work directory. Run these commands
after policy or task changes:
For a suspected relay-token leak, run agentcall rotate and restart the
listener so an already-connected socket does not keep using the old credential.
Read visibility and privacy for what each
party can observe.
Security work is active. Do not infer a guarantee from a planned issue or an
historical design document; this page describes the current implementation.
Source of truth: the README security model
is the detailed authority and should be reviewed before deployment.