Solution

Access local files with defined permissions

Use an explicit workspace boundary, protected-path rules and review controls instead of arbitrary host filesystem access.

Least privilege by project

RepoTunnel uses workspace IDs and relative paths. Absolute paths, parent traversal and symlink escapes are rejected before file operations reach the filesystem.

  • Explicit project approval
  • Protected credential files
  • Read-only mode
  • Safe editing history
  • Human-selected external-file import when needed

Why this differs from a raw shell

A raw shell starts from broad host authority. RepoTunnel instead exposes bounded capabilities whose inputs are validated against the approved workspace and current policy.

Start typing to search.