RightNow Agent runs tools locally and sends model inference to a configured provider. The shipped profile sends prompts and relevant tool results to RunInfra at https://api.runinfra.ai/v1. It is not an air-gapped product.
RIGHTNOW_API_KEY.CEREBRAS_API_KEY.Receipt projections omit header and query values, but the full effective sampling config contributes to a hash. Review every diagnostic artifact before sharing it.
remote_fetch = false disables optional model-catalog fetching only.telemetry = false does not disable model or tool traffic and does not remove the local unified log.--always-approve, --yolo, and --dangerously-skip-permissions auto-approve tool execution. Do not use them for untrusted work.
On Windows, permission prompts are application-level decisions, not kernel-enforced filesystem or network isolation. Use an external containment boundary when stronger isolation is required.
Treat repository text, command output, fetched pages, MCP output, hooks, and migrated rules as untrusted input. Review commands, paths, destinations, URLs, headers, and environment values before approval. The shipped template disables machine-wide Claude and Cursor skill, rule, and agent imports. MCP migration is opt-in.
Do not publish credentials, customer data, or exploit details in a public issue. Include the affected version and operating system, impact, reproduction steps, redacted configuration, and disclosure status when possible.
The repository security policy does not yet specify an approved private reporting channel. That placeholder must be resolved before a release directs reporters to it.