Trust

Security

Orbit runs an AI agent with local tool access on your machine, so its security model is worth stating plainly. Here is how to report a problem and what counts as one.

Last updated October 10, 2026

Supported versions

Orbit is pre-1.0. Security fixes are made against the latest release and the main branch.

  • main (latest) — supported
  • Latest tagged release — supported
  • Older releases — not supported

Reporting a vulnerability

Please report vulnerabilities privately — do not open a public issue. Use GitHub's private vulnerability reporting, or email [email protected].

What to include

  • a description of the issue and its impact;
  • steps to reproduce, or a proof of concept;
  • the Orbit version, your OS version, and how Orbit was installed (cargo run, a .app bundle, or a DMG);
  • the pi CLI version (pi --version).

What to expect

You can expect an acknowledgement within a few days and a status update as the report is triaged. Please give a reasonable window to ship a fix before any public disclosure.

Scope and security model

Orbit is a local desktop client. It spawns the pi coding agent as a child process and gives it the same local tool access you would have in a terminal. A few properties are by design and are not vulnerabilities on their own:

  • Orbit runs the agent with full local tool access. The agent can read, edit, and run commands in your workspace as your user. This is the point of the tool.
  • Access modes are a confirmation guard, not a sandbox. Supervised, Auto-accept edits, and Full access decide which mutating tool calls prompt first. pi ships no sandbox and Orbit does not add one. A mode that auto-approves a call is not an isolation boundary.
  • Session data lives in pi's own store (~/.pi/agent/, ~/.orbit-pi/). Orbit reads and writes the same files the pi CLI does.

Reports we do want:

  • memory-safety bugs;
  • command or prompt injection that crosses a boundary Orbit claims to enforce;
  • credentials leaking across the RPC surface;
  • the signed updater accepting an unverifiable artifact.