Adapted from
docs/SECURITY.mdin lumen. See Lumen for the overview.
Predictable authority: every sensitive action passes through one policy boundary (lumen-core), is explainable end-to-end, and leaves a runtime-emitted audit trail.
In scope: malicious or compromised plugins, prompt-injected model output, confused-deputy attacks via tools, secret exfiltration through tool arguments, unapproved sensitive actions.
Out of scope: protecting the host from its OS administrator, an already-compromised OS, or physical access.
The OS, the lumen-core binary, and the OS keychain are trusted. Everything else — model output, plugin code, channel input, remote provider responses — is untrusted.
Capabilities are granted explicitly by the runtime, never self-asserted by plugins. Default policy denies anything not granted. Plugin manifests declare what they want; the runtime decides what they get.
Approvals supplement policy; they do not replace it. The approval screen must show the actual effect, not a vague risk label.
An approval binds: the canonical action type and normalized arguments; resource identifiers, paths, command, working directory, destination; environment names (excluding secret values); hashes of referenced scripts/files when contents determine the action; plugin ID, version, executable hash, config hash; requesting identity, workspace, run, policy version; creation time, expiry, allowed use count.
One approval authorizes one immutable action envelope. Changing the action invalidates the approval.
Model output is untrusted input to the policy boundary, never instructions. Tools cannot be tricked into exceeding their granted capabilities because the runtime — not the tool — enforces the boundary.
Third-party code runs as WASM components or supervised subprocesses (Linux: bubblewrap profile; macOS: sandbox-exec). Cancellation, budgets, and deadlines are enforced by the kernel.
Secrets live in the OS keychain and are resolved at the executor boundary — withheld from models whenever possible, never baked into prompts or plugin-visible config.