The short version
Equinox Local is a local tool runtime, not a guarantee that an AI agent cannot make mistakes. Its management interface, structured capabilities, Terminal, browser contexts and connected providers have distinct boundaries.
A private, loopback-only management interface. No arbitrary HTTP command console.
A broad shell running as your operating-system user. Not confined to Selected roots after startup.
Separate Agent Browser and Your Browser profiles with independent consent and no silent fallback.
Full and Selected access
Fresh managed installs start Agent Access in Full mode. Root-aware structured capabilities can use accessible home or absolute folders as contained roots, with protected credential/application-secret areas, filesystem-root access, traversal and symlink escape blocked by their guards.
Selected mode limits those structured capabilities to configured projects and file roots. Relevant operations preserve bounded input/output, mutation locks and expected-SHA checks where required. Ordinary file editing, local Git, GitHub CLI, builds and package-manager work are terminal-first rather than exposed through a broad set of file/Git wrappers.
Terminal is a separate boundary
When enabled, Terminal runs as the logged-in operating-system user. It is not a Selected-root filesystem sandbox after the shell starts. Folder protections on structured operations must not be read as restrictions on arbitrary shell commands. Disable Terminal if strict selected-root containment is required.
Equinox-managed provider credentials are not injected into generic Terminal/process environments. This does not make the shell equivalent to a credential-isolated sandbox or remove the authority of the logged-in operating-system account.
Managed commands can continue after the foreground wait ends, with the same process identity for waiting, logs or explicit stop. Process lifecycle tracking is not a sandbox; deliberately detached commands can fall outside generic cleanup ownership.
Control Center stays local
The native app displays Control Center from 127.0.0.1:24891. Management APIs bind to loopback and enforce Host, same-origin, CSRF, bounded request and configuration revision checks where applicable. They are not a generic shell endpoint.
The public website is documentation and distribution only. It cannot list your projects, control Chrome or execute Local operations. There is no CORS bridge from this site into the private management API.
One extension, two contexts
Equinox Browser and Chrome Native Messaging are the product’s browser transport. Agent Browser uses a dedicated Chrome profile by default. Your Browser is personal Chrome and must be explicitly selected. Unavailable contexts fail with recovery guidance, not a silent switch to the other profile.
Install the extension separately in each profile through Chrome Web Store. Fresh installs require browser-data disclosure acceptance and explicit enablement. Turning browser control off rejects automation commands; the limited local settings channel may remain connected. Agent Browser bookmark tools do not expose personal Your Browser bookmarks.
The extension does not request broad host_permissions. It uses Chrome’s debugger API, which still has meaningful access to pages used for requested actions. Consent is not a claim that browser content is harmless or that an agent cannot perform a consequential action.
Desktop and integrations
Desktop automation is currently macOS-only. On macOS it uses a reduced operation allowlist through the bundled local engine; Screen Recording and Accessibility permissions belong to the stable Equinox Local.app identity. Windows Local v1 does not expose Desktop automation.
Optional Telegram delivery uses one configured private recipient and a private local bot token. Agents receive a message-text-only send operation, not the token, recipient override or an inbox. Groups and channels are not supported.
Task-relevant information can leave your computer when you connect AI or service providers. Their terms apply separately. Read the Privacy policy for data categories and destinations.
Verified updates and rollback
Managed Local updates verify Ed25519-signed metadata, the pinned HTTPS download path, architecture, exact artifact size, SHA-256 and archive safety before activation. Version and health are checked after restart; failed activation restores the previous release.
The initial HTTPS bootstrap verifies artifact size and SHA-256 before extraction. This installation path is a user-level shell bootstrap, not a promise of Apple notarization. Local’s managed updater does not overwrite or sideload the Browser extension; Chrome Web Store owns that update path.
Inspect or report
Review the public security model, source and tests on GitHub. These boundaries are documented design choices, not a claim that the product is vulnerability-free.
Send security reports privately to iletisim@sametbasbug.dev. Include a minimal reproduction and affected version. Do not publish credentials, private browsing data or unrelated personal information in an issue.