Hackcat

What Files, Processes, and Network Permissions Are Granted When Running Locally?

Local use operates with the system permissions of the launching user; approval options do not equate to operating system isolation.

Permissions Come from the System User Launching the Program

Hackcat Desktop and Local Agent execute commands directly on the target computer using the permissions of the user who launched the program, without container isolation. They can affect files, processes, and network resources accessible to that user, so do not interpret the term “local sandbox” as an independent testing container. It is recommended to choose a test environment under your control and first confirm the directories and targets the task can operate on.

Approval Control and System Permissions Are Two Separate Layers

Requiring approval allows you to review operations before commands or file modifications occur; full access reduces such prompts. These options do not create isolation boundaries at the system level, nor do they grant ordinary users automatic administrator privileges. If file access is denied, check the actual path and system authorizations. Do not treat switching approval modes as a way to fix system permissions, and do not assume it elevates the entire client’s permissions by default.

Narrow the Task Scope and Retain Recovery Evidence

Before sending, clearly specify allowed directories, required network usage, and files that should not be modified; keep your own backups of important content first. On first run, you can choose to require approval and review commands. Stopping a task can request termination of subsequent execution but does not roll back file modifications or network requests already completed. The model may still process task and tool outputs; local execution should not be considered as content completely staying on the computer.

Read Security and Trust Statement