Security model
Shellaro holds access to your servers, so extensions are treated as untrusted code and everything is reviewed before it is installed. This page says what that protects against and where its limits are.
Isolation
- Each extension runs in its own Web Worker created from a blob. A worker has no DOM: it cannot read Shellaro's window, settings, terminals or any other extension.
- Before extension code runs, Shellaro's bootstrap deletes and freezes
fetch,XMLHttpRequest,WebSocket,EventSource,importScripts,Worker,SharedWorker,indexedDB,caches,BroadcastChannel,WebTransport,RTCPeerConnection,Requestandnavigator.sendBeacon. Tests check that they stay unreachable (including throughglobalThis, the prototype chain,evalandFunction). - Workers cannot call Shellaro's backend: Tauri's IPC requires a key that only the page has, and the worker never receives it. The page's Content Security Policy limits connections to Shellaro's own IPC and allows workers only from
blob:. - The only way out is
postMessageto the Extension Host, which accepts the methods of the API, checks the permission for each call against what you approved, validates and trims the arguments, and performs the operation with Shellaro's own code. - A crash, a flood of errors or a hang (heartbeat) stops that extension's worker; Shellaro keeps running. Extension views are data drawn by Shellaro inside an error boundary.
What extensions never get
Passwords, passphrases, private keys or key paths, Credential Manager entries, API keys, tokens, Shellaro's settings and files, other extensions' storage, raw terminal input. There is no API for any of these.
Commands on your servers
terminal.execute and remote.exec go through Command Safety, the same engine as typed commands, with the extension named as the origin. remote.exec runs commands you do not see in a terminal, so the first command on each server asks you ("Always allow on <server>" or "Allow once"), showing the command. Consents are listed and revocable per extension.
This is still a trust decision: an extension with remote.exec that you allowed on a server can read files there with commands Command Safety considers harmless (such as cat). The review marks this permission High for that reason. Install such extensions only from publishers you trust.
The local cluster
local.cluster lets an extension ask Shellaro to create, start, stop or delete the local Kubernetes cluster. Creating and deleting always show Shellaro's confirmation. The k3s container runs privileged (Kubernetes needs it), on its own Docker network with no ports on the host; only the toolbox's SSH port is published, on 127.0.0.1.
Packages
- Integrity (SHA-256 of every file), optional Ed25519 signatures, size, path and zip-bomb checks; see packaging. The bytes installed are the bytes you reviewed.
- Downloads from sources must match the checksum the source announced; remote sources need https.
- An update cannot gain permissions or network hosts silently.
Limits, honestly
- A Web Worker is a strong boundary inside WebView2, but it is not a separate OS process or sandboxed user account. A browser-engine vulnerability that escapes a worker would affect Shellaro's window. Keep WebView2 updated (Windows does this).
- A worker can use CPU and memory until the heartbeat stops it (busy for about 8 to 23 seconds). Memory is not capped separately.
- Packages from the built-in catalog are trusted because they ship with Shellaro; packages from elsewhere are unsigned unless their publisher signs them and you trust the key.
- Command Packs contain no code, but their commands still do what they say. Read them in the Marketplace (Contents) before running; Command Safety still checks each one.