Only the target skill enters the workspace.
Tripwire stages the skill under test in a disposable agent workspace, runs with a read-only or plan-mode boundary, and removes the workspace when the probe finishes.
Security model
Tripwire observes whether a skill activates. It does not need your prompts, repository, model output, or credentials to operate the product.
Agent Skills often contain internal workflows and codebase-specific instructions. Tripwire keeps the sensitive material with the developer and reduces hosted infrastructure to a narrow, documented telemetry endpoint.
Tripwire stages the skill under test in a disposable agent workspace, runs with a read-only or plan-mode boundary, and removes the workspace when the probe finishes.
Local probes use the selected CLI’s authentication. CI secrets remain on your GitHub runner. Tripwire never proxies, stores, or logs provider credentials.
Skill contents, file paths, prompts, repository URLs, and generated commands remain in browser memory or localStorage. They are not sent to Tripwire analytics.
Completed behavioral runs may report an anonymous installation hash, command, agent, outcome, source, version, and event name. Set TRIPWIRE_TELEMETRY=0 to disable it.