Network exposure
- The web server binds to
127.0.0.1:3000by default. - The production launcher rejects requests that do not originate from loopback with
403 Loopback requests only, even if you bind another host. - There is no multi-user authentication and no token layer. Do not expose the port to untrusted networks; anyone who can reach it can drive the agent with your credentials and filesystem access.
Code execution
The agent executes real code on your machine: IPython cells, shell commands, and file edits run with your user’s permissions in the bound workspace directory. Interactive question dialogs are the approval surface for actions that ask first; unanswered dialogs time out after 60 seconds. Run Fleet in projects you trust.Credentials
Provider API keys and OAuth tokens are stored by the pinned engine under~/.prime/agent/, shared with any prime-agent install. Fleet’s web stack never stores credentials itself; the server reads them through the engine.
Runtime integrity
- The engine is installed from a release tarball pinned by version and SHA-256 in
PRIME_AGENT_RUNTIME.json;npm run checkfails if the pin and the installed dependencies drift. - On startup, the server probes the daemon socket and refuses to attach to a daemon that is not the pinned version, rather than silently driving an unexpected engine.
Known gaps
- Pending interactive dialogs are not persisted across a server restart.
- SSE replay buffers are in-memory only; sequence numbers do not survive a restart.