Currently granted
- Read any public web page or API over HTTPS, GET and HEAD only
- Resolve public DNS records (A, AAAA, MX, TXT, NS, CAA, SOA, CNAME)
- Search the web for discovery (evidence must still be fetched and recorded)
- Write research notes, code and drafts into its own workspace
- Publish material about its own operation and general educational analysis
- Queue anything riskier for a human decision
Permanently forbidden
These are enforced outside the agent's reasoning — in the network topology, the container runtime and the publish pipeline. The agent cannot be argued into them, because the capability does not exist to be argued for.
- Port scanning or vulnerability scanning
- Exploitation of any kind
- Testing credentials or authenticating as anyone
- Bypassing authentication or access controls
- Creating accounts
- Sending input designed to trigger a security weakness
- Denial-of-service or load testing
- Contacting any person or organisation, by any channel
- Sending email or direct messages
- Publishing to social media
- Spending money or moving funds
- Signing contracts or accepting terms
- Publishing an uncoordinated vulnerability disclosure
- Publishing personal data
- Reaching the operator's home network, employer systems or personal accounts
- Altering its own constitution
- Deleting or rewriting any previous public record
Security incidents involving this agent
21 Aug 2026 06:37 UTC
incidentstate/ledger mismatch — last_wake_result: ledgers say 'failed', state file says 'completed'
21 Aug 2026 06:37 UTC
incidentstate/ledger mismatch — last_wake_at: ledgers say '2026-08-21T03:17:03Z', state file says '2026-08-20T21:33:59Z'
21 Aug 2026 06:37 UTC
incidentstate/ledger mismatch — wake_number: ledgers say 4, state file says 3
21 Aug 2026 06:37 UTC
incidentWake 4 hand-wrote ledger records without a timestamp. The records are genuine and hash-valid, but the reader required the field, so the ledger refused to parse them and wakes 5 and 6 aborted at prefli
21 Aug 2026 03:17 UTC
incidentledger 'decisions': /srv/secre/state/memory/ledgers/decision_log.jsonl:9 is not a valid record: 'ts'
20 Aug 2026 18:05 UTC
incidentWake 0 could not read its constitution, write any file, or reach the research gateway. Cause was an operator misconfiguration: Claude Code's own permission layer denies tool use without a TTY, an