tencent cloud

Security Overview

Download
Focus Mode
Font Size
Last updated: 2026-09-30 18:41:47
AI-Translated

Security Methods

Security Fundamentals

The security of your code is of paramount importance. CodeBuddy Code is built with security at its core and developed in accordance with Tencent's comprehensive security program.

Permission-Based Architecture

CodeBuddy Code uses strict read-only permissions by default. When additional operations are required, such as editing files, running tests, or executing commands, CodeBuddy Code requests explicit permission. Users can control whether to approve an operation once or allow it automatically.
We designed CodeBuddy Code to be transparent and secure. For example, approval is required before bash commands are executed, giving you direct control. This approach enables users and organizations to configure permissions directly.
For detailed permission configuration, see Identity and Access Management.

Built-in Protection

To mitigate risks in intelligent agent systems:
Sandboxed bash tool: Bash sandbox isolates the file system and network access of bash commands, reducing permission prompts while maintaining security. Use /sandbox to enable it and define the boundaries within which CodeBuddy Code can work autonomously.
Write access restrictions: CodeBuddy Code can only write to the folder where it was launched and its subfolders. It cannot modify files in parent directories without explicit permission. Although CodeBuddy Code can read files outside the working directory, which is useful for accessing system libraries and dependencies, write operations are strictly limited to the project scope, creating a clear security boundary.
Prompt fatigue mitigation: Supports adding frequently used security commands to an allowlist by user, repository, or organization.
Accept edits mode: Accept multiple edits in batches while maintaining permission prompts for commands with side effects.

User Responsibilities

CodeBuddy Code only has the permissions you grant it. You are responsible for reviewing the security of suggested code and commands before approving them.

Preventing Prompt Injection

Prompt injection is an attack technique where attackers attempt to override or manipulate an AI assistant's instructions by inserting malicious text. CodeBuddy Code includes multiple defenses against these attacks:

Core Protection

Permission system: Sensitive operations require explicit approval.
Context-aware analysis: Detects potentially harmful instructions by analyzing the full request.
Input sanitization: Prevents command injection by processing user input.
Command blocklist: Blocks risky commands that fetch arbitrary content from the network by default, such as curl and wget. When explicitly allowed, note the permission mode restrictions.

Privacy Protection

We have implemented multiple safeguards to protect your data, including:
Limited retention period for sensitive information
Restrict access to user session data.
For complete details, see our Terms of Service and Privacy Policy.

Additional Protection Measures

Network request approval: Tools that make network requests require user approval by default.
Isolated context window: Web fetch uses a separate context window to prevent injection of potentially malicious prompts.
Trust verification: Trust verification is required when a codebase or a new MCP server is run for the first time.
Note:
Trust verification is disabled when a non-interactive run is performed with the -p flag.
Command injection detection: Suspicious bash commands require manual approval even if they were previously added to the allowlist.
Fail-closed matching: Commands that do not match require manual approval by default.
Natural language description: Complex bash commands include explanations to help users understand them.
Secure credential storage: API keys and tokens are encrypted. For details, see Credential Management.
Note:
Windows WebDAV security risk: When CodeBuddy Code is run on Windows, we recommend that you do not enable WebDAV or allow CodeBuddy Code to access paths that may contain WebDAV subdirectories, such as `\\\\*`. [WebDAV has been deprecated by Microsoft](https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#:~:text=The%20Webclient%20\\(WebDAV\\)%20service%20is%20deprecated) due to security risks. Enabling WebDAV may allow CodeBuddy Code to trigger network requests to remote hosts, bypassing the permission system.
Best practices for handling untrusted content:
1. Review suggested commands before approval.
2. Avoid transferring untrusted content directly to CodeBuddy.
3. Verify suggested changes to critical files.
4. Use a virtual machine (VM) to run scripts and make tool calls, especially when interacting with external Web services.
Note:
While these protections significantly reduce risk, no system is completely immune to all attacks. Always maintain good security practices when using any AI tool.

MCP Security

CodeBuddy Code allows users to configure Model Context Protocol (MCP) servers. The list of allowed MCP servers is configured in source code as part of the CodeBuddy Code settings that engineers check into source control.
We encourage you to write your own MCP servers or use MCP servers from providers you trust. You can configure CodeBuddy Code permissions for MCP servers. CodeBuddy does not manage or audit any MCP servers.

Gateway Network Security

When the HTTP service is started through --serve mode or Daemon, CodeBuddy Code uses defense in depth to protect API endpoints:

CORS Allowlist

Only cross-origin requests from legitimate sources are allowed. Requests with an invalid Origin, whether OPTIONS preflight or actual requests, are directly rejected without executing any business logic. Three configuration modes are supported: exact origin (https://example.com), subdomain wildcard (https://*.example.com), and allow all (*). Configure this through the CODEBUDDY_CODE_CORS_ORIGINS environment variable or the gateway.corsOrigins setting.

Custom Request Header Validation

All API requests must include the X-CodeBuddy-Request: 1 header. This mechanism leverages browser security policies: custom headers force a CORS preflight, and in no-cors mode, browsers do not allow custom headers to be sent, thereby preventing cross-site request forgery.
This can be disabled by setting CODEBUDDY_DISABLE_REQUEST_VALIDATION=1. For details, see HTTP API Security.

Authentication Protection

codebuddy --serve enables password authentication by default (secure by default). These endpoints include sensitive capabilities such as executing processes (/api/v1/process/*), reading and writing arbitrary files (/api/v1/files/*, /api/v1/fs/*), and interactive terminals (/api/v1/pty/*), so they no longer rely on "listening on loopback only" as a security boundary — other processes on the same machine and web pages opened in browsers can reach the loopback port.
At startup, a random password and a clickable link containing the password are printed. Clicking the link sets a session Cookie valid for 30 days. API requests must include the Authorization: Bearer <password> header or this Cookie (?password= is valid only for the homepage).
You can explicitly disable authentication with --auth none or CODEBUDDY_GATEWAY_AUTH=none, in which case a warning is printed at startup. After authentication is disabled, any process on the same machine can execute commands and read or write files through this service, so it is recommended only for isolated environments (containers / one-time sandboxes) or CI.
For details, see HTTP API Authentication.

Sandbox Security

CodeBuddy Code supports the Bash sandbox feature, which isolates bash commands from your file system and network:

Sandbox Isolation Level

File system isolation: File access is controlled through Read/Edit permissions.
Network isolation: Network access is controlled through WebFetch permissions.
Command isolation: Certain commands can be configured to run outside the sandbox.

Sandbox Configuration

{
"sandbox": {
"enabled": true,
"autoAllowBashIfSandboxed": true,
"excludedCommands": ["git", "docker"],
"network": {
"allowUnixSockets": ["/var/run/docker.sock"],
"allowLocalBinding": true
}
}
}

Sandbox Restrictions

Platform support: Currently, only macOS and Linux are supported.
Performance impact: Sandboxing may slightly affect command execution performance.
Compatibility: Some tools may not work properly in the sandbox.
See the Bash Sandbox documentation for complete configuration options.

Security Best Practices Tutorial

Handling Sensitive Code

Review all suggested changes before approval.
Use project-specific permission settings for sensitive repositories.
Regularly audit your permission settings using /permissions.
Use the sandbox feature to provide additional isolation.

Team Security

Share approved permission configurations through version control.
Train team members on security practice tutorials.
Regularly review and update permission policies.
Use project-level settings to enforce team standards.

Permission Configuration Tutorial

1. Principle of least privilege
Grant only the minimum permissions required to complete the task:
{
"permissions": {
"allow": [
"Read",
"Edit(src/**/*.ts)",
"Bash(npm:test,npm:build)"
],
"deny": [
"Edit(**/*.env)",
"Bash(rm:*)",
"Bash(sudo:*)"
]
}
}
2. Protect sensitive files
Always deny access to files that contain sensitive information:
{
"permissions": {
"deny": [
"Read(.env)",
"Read(.env.*)",
"Read(secrets/**)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Edit(**/*.key)",
"Edit(**/*.pem)"
]
}
}
3. Use WebFetch with caution.
Deny or prompt for network requests by default:
{
"permissions": {
"ask": [
"WebFetch"
],
"allow": [
"WebFetch(domain:github.com)",
"WebFetch(domain:npmjs.com)"
]
}
}
4. Limit dangerous commands
Explicitly deny commands that may cause damage:
{
"permissions": {
"deny": [
"Bash(rm:*)",
"Bash(sudo:*)",
"Bash(chmod:*)",
"Bash(chown:*)",
"Bash(curl:*)",
"Bash(wget:*)"
]
}
}

Environment Isolation

1. Use a separate development environment.
Use different environments for different security levels:
# Production code - strict permissions
cd ~/production/app
codebuddy --permission-mode default

# Experimental projects - relaxed permissions
cd ~/experiments/test
codebuddy --permission-mode acceptEdits
2. Containerized development
Use Docker containers to provide an additional security boundary:
# Run in a container
docker run -it --rm -v $(pwd):/workspace codebuddy

Code Review Process

1. Automated review precheck
Review CodeBuddy's changes before committing:
# View all changes
git diff

# Review specific files
git diff src/critical.ts
2. Use hooks for verification.
Configure pre-commit hooks to verify changes:
{
"hooks": {
"PreToolUse": {
"Edit": "npm run lint-staged"
}
}
}
3. Team code review
Important changes require review by team members:
# Create a PR instead of committing directly
git checkout -b feature/codebuddy-changes
git push origin feature/codebuddy-changes

Sensitive Data Protection

1. Use environment variables.
Do not hardcode sensitive information in code:
# Incorrect example
export API_KEY="sk-1234567890"

# Correct example - Use an environment variable management tool
export $(cat .env.local | xargs)
2. Encrypt configuration files.
Encrypt sensitive configuration files:
# Use git-crypt
git-crypt init
echo "secrets.json filter=git-crypt diff=git-crypt" >> .gitattributes
3. Rotate credentials regularly.
Rotate API keys and access tokens regularly:
# Use apiKeyHelper to obtain keys dynamically
{
"apiKeyHelper": "/usr/local/bin/get-rotating-key.sh"
}

Auditing and Monitoring

1. Log permission requests.
Track permission requests from CodeBuddy:
{
"hooks": {
"PreToolUse": {
"*": "echo \\"[$(date)] Tool: $TOOL_NAME\\" >> ~/.codebuddy/audit.log"
}
}
}
2. Review logs regularly.
Check audit logs to detect anomalies:
# View recent tool usage
tail -f ~/.codebuddy/audit.log

# Search sensitive operations
grep "Edit.*\\.env" ~/.codebuddy/audit.log
3. Permission Config Audit
Regularly review permission configurations:
# View current permissions
codebuddy config get permissions

# List all configuration files
find . -name "settings.json" -o -name "settings.local.json"

Reporting Security Issues

If you discover a security vulnerability in CodeBuddy Code:
1. Do not disclose publicly.
2. Report it through Contact Us.
3. Include detailed reproduction steps.
4. Allow time for us to resolve the issue before public disclosure.

Security Checklist

Before using CodeBuddy Code, ensure the following:
Reviewed and configured appropriate permission settings.
Sensitive files have been added to the deny list.
Dangerous commands have been blocked or require confirmation.
The sandbox feature has been enabled as needed.
Secure storage of API keys and tokens.
Team members have received security training.
A code review process has been established.
Regularly audit permission usage.
Learn how to report security issues.

Relevant Resources

Identity and Access Management - Configure permissions and access control.
Bash Sandbox - File system and network isolation for bash commands
MCP Integration - Configure MCP server permissions.
Hooks Documentation - Use hooks for custom security validation.
Settings Configuration - Complete configuration options


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback