Security

BugIt QA Agent is a human-in-the-loop assistant. It runs locally, through your assistant in VS Code or from a terminal, and acts only through the integrations you enable.

What BugIt does to protect you

  • No write without confirmation. Every create/comment/attach/notify that carries your report is previewed; irreversible filings need you to type FILE IT. Chat text alone never files, and a plain "yes" is not enough. One exception: a connection test you start yourself with notify connect, notify test or notify doctor --live sends one fixed test message without a preview, to the channel you name or, if you name none, to every channel you have switched on. It carries no report content, and dry run blocks it.
  • Dry run = read-only, everywhere your work happens. QA_AGENT_DRY_RUN=1 stops BugIt writing to your trackers and stops it reading from them: no ticket, no comment, no attachment, no notification, and no saved credential unlocked. One exception, and it is about BugIt itself rather than your data: commands you run deliberately to license or update this installation still reach BugIt's own licence server, and tools/update.py still installs the signed release it fetches, because a machine whose shell carries this variable permanently must still be able to take a security fix. Saying "dry run" in chat asks the assistant to hold off, which is useful but is not the same guarantee: only the environment variable sets the mode the code enforces.
  • No secrets in files. config.json holds orgs/URLs only; tokens live in your OS credential store. The validator flags anything secret-shaped. redact.py makes a best-effort pass to scrub emails/tokens/IPs from drafts.
  • Off by default. Every integration ships disabled; nothing connects or files until you opt in.
  • Output is data. Page/ticket/crash text is treated as data, not commands, so injected instructions are flagged and surfaced, not obeyed.

Known limits

  • Write-blocking is enforced by the agent, not the OS; the env var only hard-stops the bundled Python helpers. Run it in a trusted runtime.
  • The agent reaches whatever you connect, and credential scope = blast radius. Use least-privilege tokens.
  • Most trackers can't truly delete an issue; "undo" is limited there by design.

Hardening checklist

  1. Use a dedicated, least-privilege service account per tracker.
  2. Keep tokens in the OS store; never paste them into config.json.
  3. Run python tools/validate_config.py after setup to catch leaks/misconfig.
  4. Start only the MCP servers you use; stop the rest.

Reporting a vulnerability

Email support@bugit.dev with steps to reproduce. Do not open a public issue for security reports.

↑↓ to moveEnter to open