Project policy

Threat Model

Protected assets

Trust boundaries

The host user, configured ACP agents, configured shell commands, and explicitly managed 1MCP instances are trusted. Browser users must be authenticated through local loopback mode or a validated Cloudflare Access JWT. Remote icon and speech-provider endpoints are untrusted networks.

Primary risks

Controls

Non-goals

Trit is not a hostile multi-tenant sandbox, a privilege boundary between users on the same Unix account, or a safe way to run untrusted ACP implementations. It must not run as root or expose an unauthenticated origin listener to the internet.