DocumentationReview & control
Keep work and credentials safe
Understand what a connection can access before starting.
A Git worktree separates task changes, but is not an operating-system security sandbox. A local agent can use the tools and files it is allowed to access. Remote models receive the context required for their requests.
Step by step
Choose the intended workspace, project and computer before granting access.
Keep provider keys in the connection settings, never in prompts, project files or public topics.
Review requested actions and use task visibility for sensitive discussions.
Before sharing evidence, remove credentials, personal data and source that other people should not receive.