Skip to content

Security: Bibarud/omp-desktop

Security

SECURITY.md

Security policy

Scope

OMP Desktop is a local desktop client. It spawns one omp acp process on your machine and speaks JSON-RPC over stdio with it. It has no server component, no telemetry, and no update channel that executes code.

Reporting a vulnerability

Please open a security advisory rather than a public issue. Include the version you built (commit or release tag), your Windows version, and steps or a proof of concept.

You can expect an initial response within a week.

Design notes

  • Tool approval requests from the agent are answered by a native dialog and fail closed: if the app cannot answer, the request is rejected.
  • The app never runs shell commands itself. File and shell work is done by the omp agent process, gated by omp's own permission system.
  • Provider API keys entered on the Models page are stored by omp (environment or models.yml), not by OMP Desktop.

There aren't any published security advisories