Skip to content

Security: tini-coder/tini-agent

Security

SECURITY.md

Security

tini runs on your own machine, with your own API keys, and reads your own calendar, notes and messages. That makes a few things worth stating plainly.

What we consider in scope

  • Anything that exfiltrates keys, .env, memory (state.db), traces, or message contents off the machine.
  • Code executing at install time, or a dependency doing so.
  • A gateway or webhook accepting instructions it shouldn't — an unsigned or unauthenticated inbound request that can drive the agent.
  • Prompt injection that leads to a real side effect (a tool call, a file write, a message sent) rather than just a strange reply.

What isn't a vulnerability

  • The agent can run tools that touch your stuff. That's the product. Tools are listed in the dashboard and gated behind extras and flags.
  • TINI_EXPERIMENTAL=1 enables sub-agent delegation, which runs another coding agent locally. It's off by default and documented as experimental.
  • Your own API keys in your own .env. tini never sends them anywhere but the provider you configured.

Running it safely

  • Keep .env out of git — it's gitignored, and so are credentials.json and *token*.json.
  • Inbound gateways (WhatsApp-style webhooks) must verify request signatures before acting. Outbound ones (Telegram, Discord) dial out and aren't exposed.
  • Review a community skill or extension before installing it. A SKILL.md is instructions to a model that can call tools — read it like code.

There aren't any published security advisories