cue is an early alpha. Please do not use it with sensitive data or credentials belonging to someone else.
Please use GitHub's Report a vulnerability option in this repository's Security tab. If private reporting is unavailable, contact the maintainer privately through the GitHub profile. Do not publish exploit details or working credentials in a public issue.
For ordinary bugs and feature requests, use GitHub Issues.
- The desktop host records audio, stores keys in macOS Keychain, handles shortcuts, and writes exported files. Cloud agents run in separate Solari browsers and Linux sandboxes.
- Browser navigation tools reject non-HTTP(S) URLs and embedded credentials. This is not a network firewall: redirects and page JavaScript still run in the remote browser.
- Prompts instruct browser agents to avoid purchases, credentials, account changes, and non-search submissions. These restrictions are not enforced as transaction-level authorization; do not use this alpha with authenticated or sensitive workflows. Treat web content, generated code, and downloaded files as untrusted.
- Sandbox preview URLs are public. Do not expose secrets or private data through them. Exports persist in
~/Downloads/Cue; recent chats persist locally until deleted. Console logs can include request content, results, and URLs. - The downloadable alpha is ad hoc signed, not Developer ID signed or notarized. Source changes are not automatically included in an existing installer.
Both Bun lockfiles returned no known advisories from bun audit. An OSV scan of 541 registry packages in Cargo.lock found:
- RUSTSEC-2024-0429: GLib 0.18.5 iterator unsoundness. This Linux dependency is absent from cue’s supported
aarch64-apple-darwindependency tree. Linux is not a supported target. - RUSTSEC-2024-0370: unmaintained
proc-macro-error, also absent from that macOS tree. - Unmaintained
unic-*crates (0081, 0075, 0080, 0100, 0098), inherited through Tauri’surlpatterndependency. These maintenance advisories remain unresolved and require an upstream migration.
The source/history scan found no matches for the locally configured credentials or the credential patterns checked. These checks are limited snapshots, not a security certification; Git dependencies and undisclosed vulnerabilities are not covered by the registry scan.