Security model

Behavioral evidence
without data custody.

Tripwire observes whether a skill activates. It does not need your prompts, repository, model output, or credentials to operate the product.

Local by default is an architecture decision.

Agent Skills often contain internal workflows and codebase-specific instructions. Tripwire keeps the sensitive material with the developer and reduces hosted infrastructure to a narrow, documented telemetry endpoint.

Probe isolation

Only the target skill enters the workspace.

Tripwire stages the skill under test in a disposable agent workspace, runs with a read-only or plan-mode boundary, and removes the workspace when the probe finishes.

Credentials

Your existing agent login stays where it belongs.

Local probes use the selected CLI’s authentication. CI secrets remain on your GitHub runner. Tripwire never proxies, stores, or logs provider credentials.

Browser data

The playground and setup builder are local.

Skill contents, file paths, prompts, repository URLs, and generated commands remain in browser memory or localStorage. They are not sent to Tripwire analytics.

Anonymous telemetry

Seven allowlisted fields, with an off switch.

Completed behavioral runs may report an anonymous installation hash, command, agent, outcome, source, version, and event name. Set TRIPWIRE_TELEMETRY=0 to disable it.

Found a vulnerability? Follow the private reporting instructions in the repository security policy. Do not open a public issue with exploit details.

Read the security policy ↗