AI-facing file tools use workspace IDs plus relative paths. Absolute paths, parent traversal and symlink escapes are rejected.
AI access within approved boundaries
RepoTunnel's privileged local boundary is implemented in Rust and separates workspace access, command execution, Git publishing, browser actions, desktop control, phone access and remote transport into distinct policy surfaces.
Common environment files, private keys, credential files and secret-bearing paths are denied even inside an approved project.
Linux uses Bubblewrap, Windows uses AppContainer + Job Object, and macOS uses the current Seatbelt compatibility backend. No silent unrestricted fallback.
Remote MCP cannot approve or reject its own queued AI Review file, command or Git actions.
AI Auto is not standing permission to publish. Git push requires a current explicit human instruction and a final secret preflight.
Public access is routed through RepoTunnel's authenticated connection boundary rather than exposing the raw local gateway.
Uncertain clicks/types are reported as ambiguous instead of blindly replayed after helper transport loss.
Desktop permission is explicit and RepoTunnel itself cannot be targeted by its own AI desktop control path.
MCP cannot pair/select a different phone, raise Phone permissions or unpause AI access. Payment-sensitive foreground apps block AI control.
Read the technical security documentation
The website summarizes the model. The repository remains the canonical source for implementation details, security policy and release acceptance tests.