Security
Approval-Gated Safe Execution Model
ForgeAI Level 0 uses explicit gating and bounded execution controls. This page avoids unsupported compliance claims.
Current Controls
- Planning-only by default
- Default-deny execution
- Explicit human approval
- Explicit authorization
- Proposal-bound approval
- Approved operation IDs
- Repository-root containment
- Path traversal rejection
- Symlink rejection
- SHA256 and byte-size preconditions
- Atomic write
- Rollback on post-write failure
- Command verification remains NOT EXECUTED
- No source content or secret exposure in summaries