Supervise an AI coding agent (Claude Code / Codex / ACP) overnight and keep control: block forbidden tool calls before they run, gate 'done' on real tests, checkpoint work to git, cap spend, and get a morning report where every line is sourced. Local-first, no telemetry. Rust daemon + Tauri app + Claude Code plugin.
- capability exposure inferred + 16
- tool safety inferred + 12
inferred
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 3d ago · see ecosystem CVEs →
- C · 40 → B · 28
- C · 48 → C · 40
- C · 40 → C · 48
No known CVEs for this server.
- high hidden prompt content
1 file(s) with hidden prompt content: MalyStern-agentrelay-74437f3/i18n/README.md (hidden-unicode): "characters `‹U+2066›…‹U+2069›`. (+3 more lines)"
analyzed commit 74437f3 · analyzer v33 · 1w ago
skills & prompt files 2
- hidden: readme: hidden-unicode MalyStern-agentrelay-74437f3/i18n/README.md :118
characters `‹U+2066›…‹U+2069›`. (+3 more lines)
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of MalyStern.