Reference
Safety
What the Gray AI agent does and does not protect you from: it runs shell commands with your privileges and has no command guard.
Source: SECURITY.md
Gray executes shell commands from the model. There is no command guard and no approval prompt: the model's bash runs what it writes, with your user's privileges. There is no container or VM isolation, so run Gray in a container or VM for untrusted work.
REPL sessions keep raw transcripts at 0600 under ~/.gray/sessions for exact resume, including any secret that crossed a tool call. gray -p print mode scrubs secrets before persisting. Plan backups, snapshots and disk access accordingly.