These docs track main. Latest release: v1.0.0.
antigravity-booster
Reference

Security

agb's threat model and the boundaries that enforce it: sandboxes, environment scrubbing, sidecar authentication and on-disk state.

agb runs an LLM that writes code in your repository, executes your build and test commands against that code, and merges the result. This page states what agb trusts, what it does not, and the mechanisms in v1.0.0 that hold the line. To report a vulnerability, follow the process in SECURITY.md.

This page supersedes parts of SECURITY.md

The threat-model section of the root SECURITY.md predates the v1.0.0 sandbox and environment work: it describes gate sandboxing as macOS-only and says subprocesses inherit your whole environment. The behavior below is read from the v1.0.0 source.

Trust model

Untrusted: everything the model produces. Code, test files, package.json edits and transcript text. Model output is never passed through a shell (subprocesses are spawned with argument arrays), the merge decision comes from gates plus a JSON severity contract from a separate prosecutor rather than the builder's own claim, and a builder that rewrites the gate script is caught before merge (verifyGateScriptIntegrity).

Trusted: your plan and your machine's configuration. The gate commands in plan.json are yours and run by design. Strict mode limits them to npm test or npm run <script> (plan rule), and adlcBin cannot be set from a plan. Treat a plan you did not write like a shell script you did not write.

Trusted, human-attested: .adlc/config.json. The trust root holds the Windows sandbox bypass attestation and the attestation flags. Only a human should edit it.

Gate sandbox

Gate commands run inside the ticket worktree, where the builder could have rewritten them, so they run sandboxed (C22):

PlatformMechanismBehavior
macOSSeatbelt (sandbox-exec)Network denied; writes allowed only under the worktree and temp; the worktree's .git and node_modules stay read-only (profile).
Linuxbubblewrap (bwrap)Same policy: --unshare-net, host read-only, worktree and temp writable, .git and node_modules re-bound read-only (C22).
WindowsnoneNo gate sandbox exists, so a sandboxed gate is refused.

Fail closed. When a sandbox is requested but none is usable (no bwrap installed, user namespaces disabled, Windows), the gate does not run; it returns a failure that tells you why (C22). The only way past this is AGB_SANDBOX_GATES=0, which runs gates unsandboxed with your full privileges. Set it only inside a disposable container that is itself the isolation boundary.

Because network is denied, a gate that needs to download dependencies or reach a service fails under the sandbox. Install dependencies before the run.

Builder sandbox

Builders always run with agy's --sandbox, and agb also wraps the agy process: Seatbelt on macOS (writes limited to the worktree and temp, reads of ~/.ssh, ~/.aws, ~/.gnupg, ~/.npmrc, ~/.netrc and similar denied) and bubblewrap on Linux. On macOS and Linux an unsandboxed builder is refused; there is no override (builder rule).

On Windows a builder may run without a sandbox only with a valid sandboxBypassAttestation in .adlc/config.json: an HMAC-SHA256 signature over the attestation payload, keyed by ADLC_ADMIN_KEY, with a single-use nonce (C22, HMAC check). agb doctor reports whether the attestation verifies. Setting AGB_REQUIRE_DRIVER_SIGNATURE=1 makes doctor require a signed driver attestation as well.

See Gates and sandboxing for the full picture.

Environment

Builders get a scrubbed environment (C23). Only allowlisted variables (PATH, HOME, USER, LANG, TERM, NODE_ENV, TMPDIR, git isolation variables) and AGB_* / ADLC_* variables pass, and even those are dropped when they are a listed secret (ADLC_ADMIN_KEY, ADLC_MANIFEST_KEY, GITHUB_TOKEN, GH_TOKEN, NPM_TOKEN, AWS keys, GEMINI_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY) or their name matches KEY|TOKEN|SECRET|PASSWORD|AUTH|CREDENTIAL|PRIVATE|CERT. Runtime-injection variables such as NODE_OPTIONS, LD_PRELOAD and DYLD_INSERT_LIBRARIES are always dropped (C23).

Gate commands get the full environment of the agb process (runGate env). The sandbox denies them network access, which limits exfiltration, but they can read every exported variable. Run agb from a shell that does not export credentials you would not hand to your test suite.

Sidecar dashboard

agb sidecar serves the dashboard on 127.0.0.1 only (listen) and generates a random 128-bit token per session. The page (/) requires ?token=; the event stream (/events) requires the token as a bearer header or query parameter; both comparisons are constant-time (token checks).

ANTIGRAVITY_SIDECAR_WEB_PORT disables the token check

ANTIGRAVITY_SIDECAR_WEB_PORT is real. It selects jetski mode and the port (default 3333) in the sidecar launcher (C3), and whenever it is set the server skips the token check for both / and /events (C3). It is set only by the Antigravity jetski launcher, which hosts the dashboard inside the app; the server still binds to 127.0.0.1, so it is reachable only from your machine. Never set it by hand: doing so turns off dashboard authentication for any local process or browser page that can reach the port.

Data on disk

Transcripts, run state and reports under .booster/ are plaintext. They contain full prompts and model output, which can quote any file the model read, including a .env. agb forces .booster/ and its log directories to 0700 and files to 0600, and gitignores .booster/ (ownerOnlyDir). Treat the directory as sensitive and delete old run logs you do not need. See File layout and Log formats.

Uncommitted changes

agb refuses to start on a dirty working tree unless AGB_ALLOW_DIRTY=1. Commit or stash your work first; the override exists for automation that knows its tree state.

Rails and the policy guard

Rails declared by active tickets are enforced three ways: the in-session policy guard denies agent edits to rail paths, adlc rails-guard checks diffs before dispatch and merge, and CI runs the same check. Enforcement gates fail closed when rails are declared. See Rail enforcement and Policy guard.

On this page