AI on your desktop: secure automation using capture checking
Session Abstract
Local AI assistants like OpenClaw run with shell, browser, and credentials. Open chats make prompt injection a massive leak risk. Docker fails; approvals kill UX. TACIT opened the way: capture checking makes leaking information flows uncompilable.
In this talk, we will demo assistant security on browser automations against exploits.
Session Description
In this highly practical, demo-driven session, we will move from an exploit to a complete type-safe wrap:
1. The Live Exploit
We will reproduce a live prompt-injection attack against an unsandboxed OpenClaw instance. We’ll show how a benign-looking incoming chat message tricks the agent into harvesting host tokens and broadcasting them to an external endpoint.
2. The Zero-Rewrite MCP Wrap
We will walk through a 5-step architectural setup that intercepts agent actions over local MCP, disables built-in shell/file/network access, and routes all operations through TACIT’s capability-typed REPL.
3. Under the Hood: Scala 3 Capture Checking
We’ll tour the bleeding-edge static analysis machinery making this possible. Files under classified paths are automatically wrapped in a Classified[String] container. We will look at how the trait API leverages Scala 3 capture checking:
`scala
trait Classified[+T]:
def map[B](op: T ->{any.rd} B): Classified[B]
`
The pure ->{any.rd} function arrow enforces at compile time that the mapping operation captures no escaping capabilities. You can safely map over the data or pass it to a trusted local LLM via chat(Classified[String]), but passing it to a cloud-facing chat(String) or shipping it over HTTP will fail to compile.
4. Scaling Beyond OpenClaw
Because our security lever is the standard MCP protocol rather than application-specific code, this exact pattern generalizes. We will demonstrate the identical wrap instantly safeguarding other popular tools like Open Interpreter, Goose, and Cline.
5. Plugging the Browser Side-Channel
A wrap that only covers standard I/O leaves the web browser open as an escape hatch—an injected agent could easily navigate to local file paths or screenshot a sensitive app and ship the raw image to a cloud API. We will debut an origin-scoped BrowserPermission capability (built on Playwright) that introduces Classified[Page] and Classified[Image] boundaries. We will live-extend TACIT with under 30 lines of code to render this advanced browser leak path completely uncompilable.
Key Takeaways
You will leave this talk with:
1. The MCP Security Blueprint: A concrete, repeatable recipe for wrapping and securing any MCP-compliant agent without touching its source code.
2. A Shift from Containment to Proof: A clear understanding of why traditional runtime sandboxing (Docker/WASM) cannot stop cognitive LLM exploits, and how information-flow control plugs the gap.
3. Production-Ready Capabilities: A practical framework for shipping autonomous AI tools to non-technical users without risking leaked keys or compromised environments.