Security model
Parolsh is a frontend: it runs your shell commands and talks to an agent. It does not decide what the agent may do. This page says what Parolsh protects, and what it leaves to the agent.
Parolsh is not a sandbox
The agent runs as a normal process of your user, with your files, your network and the environment Parolsh has. Parolsh offers it no tools of its own (no file access, no terminal through ACP): the agent reads, writes and runs commands with its own tools, under its own rules.
Whatever limits the agent is the agent's: Claude's permission modes, Codex's
sandbox (read-only, agent, agent-full-access), and so on. Pick the
agent's mode for the trust you want, and check what that
mode allows in the agent's own documentation.
Permission prompts come from the agent
When the agent asks before acting, Parolsh shows its request and its options
(see During a turn). The agent decides when to ask:
Parolsh does not see what the agent does without asking, and cannot stop it.
In a mode that skips the prompts (bypassPermissions, agent-full-access),
nothing is asked.
At the prompt, anything other than one of the numbers rejects once.
!command runs as typed
!command, !+command, !bash and plain lines in shell mode go to your
shell exactly as you typed them, with no check and no confirmation, the same
as typing them in bash.
What reaches the agent
Only what you send:
- the text you type for the agent;
- the output of each
!+commandsince your last message: its stdout and stderr, the last 16 KB at most, without terminal escape sequences, with the command, its directory and its exit code; - the current directory, when a conversation starts.
The output of !command and of !bash is never sent. The agent can still
read your files and run commands with its own tools, see
above.
The agent's environment
The agent inherits Parolsh's environment, which includes the API keys and
other secrets your shell exports. With shell_env (see
Shell environment), Parolsh imports what
~/.profile and ~/.bashrc set up even when it was not started from a shell.
On top of that, the agent gets its env from the global configuration.
Keep secrets the agent does not need out of the environment you start Parolsh from.
Project configuration
A .parolsh/config.toml comes with the directory, often from a repository
you cloned. It can change how Parolsh looks and pick one of the agents you
configured, but not what is executed: shell and the agents' command,
args and env are only read from your global configuration. See
What a project can change.
Looking back
#audit lists what ran on your machine, what reached the agent and what the
agent reported doing, for the current run (see
#audit).
The ACP log
PAROLSH_ACP_LOG writes the whole conversation to a file, including what you
share with !+. Parolsh creates it readable only by you; delete it when you
are done (see
Logging the agent's messages).