TuxNestGet TuxNest
TuxNest guide

Security

Tool policy reduces risk but is not an operating-system sandbox.

Original TuxNest penguin
01Workspace boundaries

Path validation, symlink/junction checks and scope rules constrain built-in file operations.

02Approvals

Protected commands, internet, sensitive, destructive, privileged and custom actions require policy decisions.

03Secrets

Credential-like data is redacted from visible/persisted tool evidence; SSH secrets use VS Code SecretStorage.

04Remote endpoints

Any selected remote/API model receives the prompt and context you send. Use endpoints you trust.

05Shell

Approved commands execute with your OS account privileges; inspect them before allowing.