TerminaLink security

TerminaLink separates workspace commands, controlled Host Observation and explicitly approved Full system access access. The local service enforces the policy on the computer you connect. Contact support@terminalinkmcp.com privately to report a security issue.

Workspace sandbox by default

Choose a workspace before protected execution. Commands can read, edit and delete files within that boundary, run builds and tests, and start processes under the active policy. Sensitive configuration paths have extra protection. An unavailable sandbox or unsupported policy rejects the operation. TerminaLink does not rerun it on the unrestricted host.

The policy is stored outside the workspace. Prompts and tool arguments cannot enable Full system access or change the policy. The authenticated dashboard sends human control requests and displays state confirmed by the local service. The relay and owner account are trusted parts of that control path.

Host Observation and Full system access

Host Observation uses fixed operations for system information, process names and IDs, network interfaces and storage status. It does not run model-supplied host shell commands. You can turn it off. Exact host-file reads require separate approval and are supported on Linux and Windows, not macOS.

Full system access is off by default. You must approve it in the dashboard after a warning. Options are 15, 30 or 60 minutes, or until disabled. Every option also requires renewal from the activating, visible dashboard page; the grant ends within 45 seconds without renewal. Expiry, disconnect, restart or explicit disable revokes the grant. Commands must separately request Full system access scope; the default stays sandbox.

Full system access uses the local service account's normal permissions, not automatic Administrator or root access. It can change or delete accessible host data. Ending a grant cannot undo earlier actions or remove persistence created by an unrestricted command.

Platform support

  • Linux: Bubblewrap and seccomp provide workspace isolation. Working user namespaces and the native dependencies are required. Blocked, restricted and open network policies are supported. Restricted mode uses an HTTP/SOCKS domain allowlist; open mode uses proxy-based TCP access, not unrestricted UDP. Network permission does not publish a development-server port.
  • Windows: a dedicated sandbox identity, restricted token, ACLs and Windows Filtering Platform enforce the workspace and network policy. Blocked, restricted and open network modes are supported. A one-time local setup approval is required. Missing dependencies or an unavailable boundary reject protected commands; there is no unrestricted fallback.
  • macOS: the Seatbelt backend supports open networking only. Blocked and restricted modes, and approved host-file reads, are not supported and are rejected. Platform controls differ from Linux.

Check the selected device's capabilities in the dashboard. A sandbox boundary does not guarantee compatibility with every operating-system version or application. Keep sensitive material outside the selected workspace and allow only the network access the task needs.

Authentication and routing

  • The local service makes an outbound authenticated WebSocket connection. No public inbound machine port is required. Its local MCP endpoint listens on loopback and requires an independent random token.
  • Hosted access checks signed tokens for expiry, issuer, audience and scope. Browser sign-in uses authorization code, PKCE, state, nonce and browser-bound cookies.
  • Pairing claim tokens are separate from human approval codes. Pairings cannot be transferred between accounts. Relay credentials are stored as hashes.
  • Requests are checked against account ownership, credential identity and the current socket. Existing MCP sessions stay bound to their original device. An offline target does not trigger fallback to another machine.
  • Dashboard changes require session authentication, CSRF and Origin checks. Tokens are not placed in dashboard links or browser storage.
  • Stripe Checkout uses a server-controlled customer and an exact US$18 monthly USD Price. Signed payment events are reconciled against Stripe state. Browser redirects cannot grant paid access.

Data and operational limits

HTTPS and secure WebSockets protect transport. The relay can process commands and returned content while forwarding them; this is not end-to-end encryption that hides content from the relay. Relay command history is not intentionally stored. See the Privacy notice for retention and other providers.

Output, requests, sessions and input buffers have bounds. Timeout and Stop terminate the process tree where supported. A Full system access command that deliberately detaches into another service or privilege context can outlive ordinary process-tree cleanup. Review actions, protect secrets and keep backups. Untrusted project content can mislead an AI, and permitted operations can still damage accessible data.

Private reports

Email support@terminalinkmcp.com with the subject Security report. Include the version, impact and safe reproduction using harmless data on a system you control. Do not post credentials, terminal content or exploit details publicly. No response deadline, reward program, independent security certification or OpenAI endorsement is implied.