# Security Implications of the safe_mode Parameter in Open Interpreter

> Understand the security implications of Open Interpreter's safe_mode parameter. Learn how off ask and auto settings protect you from malicious code execution.

- Repository: [Open Interpreter/open-interpreter](https://github.com/openinterpreter/open-interpreter)
- Tags: security
- Published: 2026-03-05

---

**The `safe_mode` parameter in Open Interpreter controls whether code generated by LLMs is scanned by Semgrep before execution, offering three settings—`off` (no protection), `ask` (user-prompted scanning), and `auto` (automatic scanning)—that directly determine your exposure to malicious code execution.**

Open Interpreter is an open-source framework that allows large language models to run code directly on your host machine. Because this capability inherently exposes your system to significant risks—from data exfiltration to arbitrary code execution—the **`safe_mode`** parameter serves as the primary security lever, governing how and when outgoing code is inspected before it runs.

## How safe_mode Works: The Three Security Levels

The `safe_mode` parameter accepts one of three string values, each representing a distinct security posture. According to the source code in [`interpreter/core/core.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/core/core.py) (lines 50‑57), the default is `"off"`, but this can be overridden during initialization or via the CLI `--safe` flag.

### off Mode: Maximum Risk

When `safe_mode` is set to `"off"`, Open Interpreter performs **no safety checks** on generated code. The LLM's output is presented to the user (or executed directly if `auto_run` is enabled) exactly as produced. This mode offers maximum flexibility but provides **zero protection** against malicious payloads, allowing dangerous operations like file deletions, network requests, or system modifications to proceed unchecked.

### ask Mode: User-Controlled Protection

Setting `safe_mode` to `"ask"` enables **interactive scanning**. Before any code block executes, the terminal interface prompts: `Would you like to scan this code? (y/n)` (implemented in [`interpreter/terminal_interface/terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/terminal_interface/terminal_interface.py), lines 200‑207). If you confirm, the interpreter invokes `scan_code()` to run a Semgrep analysis; if you decline, execution proceeds without inspection. This mode balances security with performance, letting you decide per-snippet whether the potential risk warrants a scan.

### auto Mode: Hands-Off Protection

The `"auto"` setting provides **automatic protection** by scanning every incoming code block with Semgrep before prompting for execution. As implemented in [`terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/terminal_interface.py), when `safe_mode == "auto"`, the `should_scan_code` variable is automatically set to `True`, triggering a silent scan (lines 200‑207). If Semgrep detects issues, a warning is printed; otherwise, the scan completes without interrupting your workflow. This mode ensures continuous protection but may introduce slight delays during code execution.

## Implementation Details in the Codebase

Understanding where and how `safe_mode` is enforced reveals its security boundaries and potential limitations.

### Configuration and Defaults

The default value is defined in [`interpreter/core/core.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/core/core.py) at line 50, where the `Interpreter` class initializes `self.safe_mode = "off"`. This can be modified programmatically:

```python
from interpreter import interpreter
interpreter.safe_mode = "auto"  # Enable automatic scanning

```

### Terminal Interface and User Prompts

The `terminal_interface()` function in [`interpreter/terminal_interface/terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/terminal_interface/terminal_interface.py) handles the user-facing aspects. At startup (lines 60‑66), it displays a banner notifying users when safe mode is active and reminds them that `semgrep` must be installed (`pip install semgrep`) for scanning to function. If Semgrep is missing, the mode effectively behaves as `off`.

### Critical Interaction with auto_run

A vital safety check exists in [`interpreter/terminal_interface/start_terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/terminal_interface/start_terminal_interface.py) (lines 420‑424): **if both `safe_mode` and `auto_run` are enabled, the system forces `auto_run` to `False`**. This prevents the dangerous scenario where code is automatically executed without prior human review or security scanning.

### The Semgrep Scanning Engine

The actual security analysis occurs in [`interpreter/core/utils/scan_code.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/core/utils/scan_code.py) (lines 30‑48). The `scan_code()` function:

1. Writes the code snippet to a temporary file
2. Executes `semgrep --config auto` against it
3. Captures the output and exit code

If Semgrep returns a non-zero exit code (indicating findings), the user sees an error summary (lines 53‑56). In `auto` mode, successful scans print a "**Code Scanner:**" prefix to confirm the check occurred without findings.

### LLM-Generated Safety Tags

Complementary to `safe_mode`, some LLM outputs may contain XML tags like `<safe>`, `<warning>`, or `<unsafe>`. The streaming handlers in [`interpreter/core/llm/run_tool_calling_llm.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/core/llm/run_tool_calling_llm.py) and [`run_function_calling_llm.py`](https://github.com/openinterpreter/open-interpreter/blob/main/run_function_calling_llm.py) (lines 11‑18) strip these tags and emit `review` messages. While independent of the Semgrep-based `safe_mode`, these tags provide additional metadata that downstream tools can use for risk assessment.

## Security Trade-offs and Considerations

### Attack Surface Reduction

Without safe mode (`off`), a compromised or malicious LLM could generate code to install backdoors, exfiltrate environment variables, or destroy data. Enabling `ask` or `auto` forces a **static analysis step** that catches dangerous patterns—such as usage of `os.system`, `subprocess` calls, or suspicious network activity—before execution.

### Dependence on Semgrep Rules

The effectiveness of safe mode hinges entirely on the quality of Semgrep's auto-generated rule set (`--config auto`). While this provides sensible defaults for common vulnerabilities, it may miss novel attack vectors or zero-day exploits. Additionally, false positives could desensitize users to warnings, potentially leading to automated dismissal of legitimate alerts.

### Performance and Usability Impact

- **`ask` mode**: Adds friction by requiring a prompt for every code snippet, which may interrupt development flow during trusted, repetitive tasks.
- **`auto` mode**: Introduces execution delays proportional to code snippet size, as Semgrep runs as a subprocess for every block.

### Dependency Requirements

Safe mode requires the `semgrep` package to be installed separately. If missing, the interpreter warns the user at startup (line 62‑64 in [`terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/terminal_interface.py)) but continues operation effectively in `off` mode, creating a silent security gap if users ignore the warning.

## Practical Configuration Examples

Enable safe mode programmatically or via CLI:

```python

# Enable interactive scanning (ask mode)

from interpreter import interpreter
interpreter.safe_mode = "ask"

# Enable automatic scanning (auto mode)

interpreter.safe_mode = "auto"

# Disable all protection (high risk)

interpreter.safe_mode = "off"

```

Command-line usage:

```bash

# Start with automatic safe mode

interpreter --safe=auto

# Or use ask mode

interpreter --safe=ask

```

Example session flow in `ask` mode:

```text
> print("Hello World")

  print("Hello World")

Would you like to scan this code? (y/n) y

Code Scanner: 0 findings

Would you like to run this code? (y/n)

```

## Summary

- The `safe_mode` parameter is Open Interpreter's primary defense against malicious code execution, with three distinct levels: `off`, `ask`, and `auto`.
- **Never use `off`** in production or with untrusted LLMs, as it permits arbitrary code execution without inspection.
- **`auto` mode** provides the strongest security guarantee by enforcing Semgrep scans on every code block, but requires the `semgrep` package and adds execution latency.
- Safe mode **automatically disables `auto_run`** (as enforced in [`start_terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/start_terminal_interface.py) lines 420‑424) to prevent unsupervised execution.
- The security mechanism relies on Semgrep's rule database, which offers good coverage of common vulnerabilities but is not infallible against sophisticated or novel attacks.

## Frequently Asked Questions

### What happens if I enable safe_mode but don't have Semgrep installed?

If Semgrep is not installed, Open Interpreter prints a warning at startup stating that safe mode requires `semgrep`, then continues execution as if `safe_mode` were set to `off`. You must install Semgrep separately (`pip install semgrep`) for the security scanning to function.

### Does safe_mode prevent all malicious code execution?

No. Safe mode uses Semgrep with the `--config auto` rule set, which catches common dangerous patterns but cannot guarantee detection of all malicious code, zero-day exploits, or obfuscated attacks. It significantly reduces risk but should be combined with other security practices like running in sandboxed environments.

### Why does enabling safe_mode disable auto_run?

As implemented in [`interpreter/terminal_interface/start_terminal_interface.py`](https://github.com/openinterpreter/open-interpreter/blob/main/interpreter/terminal_interface/start_terminal_interface.py) (lines 420‑424), enabling safe mode forces `auto_run` to `False` to prevent the dangerous combination of automatic execution with automatic scanning. This ensures a human review step always occurs between the security scan and code execution.

### Can I use safe_mode with the OpenAI API or other remote models?

Yes. The `safe_mode` parameter functions at the interpreter level, independent of which LLM provider you use. Whether using local models or APIs like OpenAI, the code generated by the model is still passed through the same Semgrep scanning pipeline before execution when safe mode is active.