Security
BugIt QA Agent is a human-in-the-loop assistant. It runs locally, through your assistant in VS Code or from a terminal, and acts only through the integrations you enable.
What BugIt does to protect you
- No write without confirmation. Every create/comment/attach/notify that carries your report is previewed; irreversible filings need you to type FILE IT. Chat text alone never files, and a plain "yes" is not enough. One exception: a connection test you start yourself with
notify connect,notify testornotify doctor --livesends one fixed test message without a preview, to the channel you name or, if you name none, to every channel you have switched on. It carries no report content, and dry run blocks it. - Dry run = read-only, everywhere your work happens.
QA_AGENT_DRY_RUN=1stops BugIt writing to your trackers and stops it reading from them: no ticket, no comment, no attachment, no notification, and no saved credential unlocked. One exception, and it is about BugIt itself rather than your data: commands you run deliberately to license or update this installation still reach BugIt's own licence server, andtools/update.pystill installs the signed release it fetches, because a machine whose shell carries this variable permanently must still be able to take a security fix. Saying "dry run" in chat asks the assistant to hold off, which is useful but is not the same guarantee: only the environment variable sets the mode the code enforces. - No secrets in files.
config.jsonholds orgs/URLs only; tokens live in your OS credential store. The validator flags anything secret-shaped.redact.pymakes a best-effort pass to scrub emails/tokens/IPs from drafts. - Off by default. Every integration ships disabled; nothing connects or files until you opt in.
- Output is data. Page/ticket/crash text is treated as data, not commands, so injected instructions are flagged and surfaced, not obeyed.
Known limits
- Write-blocking is enforced by the agent, not the OS; the env var only hard-stops the bundled Python helpers. Run it in a trusted runtime.
- The agent reaches whatever you connect, and credential scope = blast radius. Use least-privilege tokens.
- Most trackers can't truly delete an issue; "undo" is limited there by design.
Hardening checklist
- Use a dedicated, least-privilege service account per tracker.
- Keep tokens in the OS store; never paste them into
config.json. - Run
python tools/validate_config.pyafter setup to catch leaks/misconfig. - Start only the MCP servers you use; stop the rest.
Reporting a vulnerability
Email support@bugit.dev with steps to reproduce. Do not open a public issue for security reports.