workplane is a single-user tool. It trusts everyone who can reach its port and everything you point an agent at. Read this before you expose the server or start an agent.
work run starts a coding agent on your machine, in a git worktree, with your user's permissions: your home directory, your gh login and every secret in the environment of the shell that ran work run. The agent pushes a branch and opens a PR with your credentials. The server itself never starts a process and never writes to GitHub.
- An unattended agent cannot answer approval prompts, so
work runrefuses to start untilapproval_modeis set in[runner]. For omp that means"yolo": no prompts. Setting it is you accepting everything on this page. - Issue and comment text is untrusted input and goes into the agent's prompt. A hostile comment can steer an agent that holds your token. Only run agents on issues you have read.
- Nothing isolates a run from the rest of your machine yet. That is the isolation roadmap. Until it lands, work with repositories you don't control under a separate OS user or in a VM.
- The server listens on
127.0.0.1unless you setHOST.HOST=0.0.0.0, a reverse proxy ortailscale serveexposes it to everything that can reach the port. - There is no authentication. Anyone who can reach the port can read every item title, including those from private repositories, and can change the queue. They cannot start an agent: runs are started by the
workCLI on a machine you control, never by the server. Rely on loopback or your tailnet's access rules until API authentication lands. - A form post that another website made your browser send is refused: its
Originmust be the server's own, or listed inallowed_origins. Redirect targets taken from forms must be paths on this server.
Report it privately through GitHub: on the repository page, Security → Report a vulnerability. Please include how to reproduce it. Only the latest release is supported.