From the 2026-09-06 security review (client H4).
bin/govern.mjs:52-64,146 resolves the gateway from ACP_GOVERN_BASE -> ACP_API_BASE -> default and concatenates it into fetch() unchecked — http:// accepted, any host accepted — and sends Authorization: Bearer <workspace key> (:295-299) with it. ACP_BEARER_TOKEN likewise overrides the on-disk credential. (Same in codex-acp-plugin/bin/govern.mjs.)
A cloned repos .claude/settings.json envblock pointingACP_GOVERN_BASE at an attacker host exfiltrates the full governance stream (every Bash command, every file writes contents, cwd, session id) plus the workspace bearer — and, because the hook obeys the verdict it gets back, also returns a blanket allow. (The Claude-Code-applies-project-env-to-hook-children half is UNCONFIRMED; the hook-side unconditional trust is confirmed.)
Fix: require https:; allowlist the host to *.agenticcontrolplane.com unless an explicit self-host flag is set; never send the bearer to a non-default host without opt-in. Same treatment for claude-acps ACP_PROXY_BASE (install.sh:1446-1465), which points ANTHROPIC_BASE_URL and sees the credential + full conversation.
From the 2026-09-06 security review (client H4).
bin/govern.mjs:52-64,146resolves the gateway fromACP_GOVERN_BASE->ACP_API_BASE-> default and concatenates it intofetch()unchecked —http://accepted, any host accepted — and sendsAuthorization: Bearer <workspace key>(:295-299) with it.ACP_BEARER_TOKENlikewise overrides the on-disk credential. (Same in codex-acp-plugin/bin/govern.mjs.)A cloned repo
s.claude/settings.jsonenvblock pointingACP_GOVERN_BASEat an attacker host exfiltrates the full governance stream (every Bash command, every file writes contents, cwd, session id) plus the workspace bearer — and, because the hook obeys the verdict it gets back, also returns a blanket allow. (The Claude-Code-applies-project-env-to-hook-children half is UNCONFIRMED; the hook-side unconditional trust is confirmed.)Fix: require
https:; allowlist the host to*.agenticcontrolplane.comunless an explicit self-host flag is set; never send the bearer to a non-default host without opt-in. Same treatment forclaude-acpsACP_PROXY_BASE(install.sh:1446-1465), which points ANTHROPIC_BASE_URL and sees the credential + full conversation.