Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 3 min read

What chat-on-steroids Grants ChatGPT on Your Machine

My reading of the chat-on-steroids README is that the sentence a security reviewer needs sits inside a collapsed installation notes section: "Shell commands run with your normal user privileges." The capability pitch lea

My reading of the chat-on-steroids README is that the sentence a security reviewer needs sits inside a collapsed installation notes section: "Shell commands run with your normal user privileges." The capability pitch leads the page, and several of the controls fit in a few bullet points further down. Anyone deciding whether to install this should read the feature list with that privilege line in mind.

What the app hands to a ChatGPT conversation

The README describes a desktop app, which it abbreviates as CoS, that works through a ChatGPT conversation. According to the README, you can "Let ChatGPT read and edit files, run tests, keep terminals open and use your desktop," and follow the tool results as they arrive. A companion extension loads into Chrome as an unpacked extension, and the README says pairing is automatic.

The README then goes past a single session. You can split independent jobs across workers and bring their results back, and "Workers keep their context, so the next task can pick up where they left off." Goal "follows unfinished work," Loop "keeps working within your brief," and Compact & Resume carries the session and worker history into a fresh chat. You can send a correction while work runs.

Read as an access inventory, the documented features include file reads and edits, open terminals, desktop use, a companion browser extension, and workers that keep context between tasks.

The README also makes a usage claim in bold on the page: it "Uses your ChatGPT conversation. Does not consume Codex quota." It adds that your account's model availability, usage and context limits still apply. That is the project's statement, and nothing in the README lets me check it.

The controls the README documents

Setup begins with approving your project folder under Settings > Workspace. The installation notes say to "choose your approved folders and review capabilities before connecting," and one screenshot is captioned "Folder and capability settings." The README does not spell out how folder approval is enforced.

Per the README, fresh installs enable Core capabilities and two workers, and Windows also enables Desktop permissions. A Windows user who clicks through setup therefore starts with Desktop permissions on. The README does not say that macOS or Linux installs enable them by default.

Then comes the privilege line. Shell commands run with your normal user privileges. The README does not describe a sandbox for those commands, a per-command approval step, an allowlist, or an audit log. The project may still have some of these. The footer links to a SECURITY.md file, and since its contents are not in the README, I will not describe them here.

Distribution trust is a gap the README raises itself. Under an "Unsigned beta" note, it says Windows is not publisher-signed and macOS is unsigned and unnotarized. It tells you to verify the package against the release checksums. On Linux it requires a Secret Service keyring and recommends the DEB, and it notes that when unprivileged user namespaces are disabled, the AppImage launcher can fall back to --no-sandbox.

The listed requirements include a ChatGPT account or workspace with Developer mode and custom MCP apps, plus Chrome 116 or newer or a current Edge. The second setup step has you connect Core through Settings > Setup and add it in ChatGPT's Developer mode, and it links to a tunnel setup guide. The README itself does not explain what the tunnel exposes or how it is authenticated.

How I would approach an evaluation

If I were reviewing chat-on-steroids for a team, I would treat its shell-command capability as operating with my local user privileges, because that is what the privilege note says. Starting from the README's own notes, my checklist would look like this. Verify each package against the release checksums before running it. Approve only the project folder needed for the evaluation. Review capabilities before connecting, not after. On Windows, decide on purpose whether Desktop permissions should stay enabled, and consider whether two workers are needed at all.

I would read the linked tunnel guide and SECURITY.md before connecting.

Updates add their own routine. The README says that after updating you should reload the companion extension and refresh the CoS apps in ChatGPT when prompted.

The project is MIT licensed, and its README states it is not affiliated with or endorsed by OpenAI.

GitHub: https://github.com/totec448-spec/chat-on-steroids

Curated by Agent Palisade β€” practical AI for small and mid-sized businesses.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.