Security Implications of the safe_mode Parameter in Open Interpreter

The safe_mode parameter in Open Interpreter controls whether code generated by LLMs is scanned by Semgrep before execution, offering three settings—off (no protection), ask (user-prompted scanning), and auto (automatic scanning)—that directly determine your exposure to malicious code execution.

Open Interpreter is an open-source framework that allows large language models to run code directly on your host machine. Because this capability inherently exposes your system to significant risks—from data exfiltration to arbitrary code execution—the safe_mode parameter serves as the primary security lever, governing how and when outgoing code is inspected before it runs.

How safe_mode Works: The Three Security Levels

The safe_mode parameter accepts one of three string values, each representing a distinct security posture. According to the source code in interpreter/core/core.py (lines 50‑57), the default is "off", but this can be overridden during initialization or via the CLI --safe flag.

off Mode: Maximum Risk

When safe_mode is set to "off", Open Interpreter performs no safety checks on generated code. The LLM's output is presented to the user (or executed directly if auto_run is enabled) exactly as produced. This mode offers maximum flexibility but provides zero protection against malicious payloads, allowing dangerous operations like file deletions, network requests, or system modifications to proceed unchecked.

ask Mode: User-Controlled Protection

Setting safe_mode to "ask" enables interactive scanning. Before any code block executes, the terminal interface prompts: Would you like to scan this code? (y/n) (implemented in interpreter/terminal_interface/terminal_interface.py, lines 200‑207). If you confirm, the interpreter invokes scan_code() to run a Semgrep analysis; if you decline, execution proceeds without inspection. This mode balances security with performance, letting you decide per-snippet whether the potential risk warrants a scan.

auto Mode: Hands-Off Protection

The "auto" setting provides automatic protection by scanning every incoming code block with Semgrep before prompting for execution. As implemented in terminal_interface.py, when safe_mode == "auto", the should_scan_code variable is automatically set to True, triggering a silent scan (lines 200‑207). If Semgrep detects issues, a warning is printed; otherwise, the scan completes without interrupting your workflow. This mode ensures continuous protection but may introduce slight delays during code execution.

Implementation Details in the Codebase

Understanding where and how safe_mode is enforced reveals its security boundaries and potential limitations.

Configuration and Defaults

The default value is defined in interpreter/core/core.py at line 50, where the Interpreter class initializes self.safe_mode = "off". This can be modified programmatically:

from interpreter import interpreter
interpreter.safe_mode = "auto"  # Enable automatic scanning

Terminal Interface and User Prompts

The terminal_interface() function in interpreter/terminal_interface/terminal_interface.py handles the user-facing aspects. At startup (lines 60‑66), it displays a banner notifying users when safe mode is active and reminds them that semgrep must be installed (pip install semgrep) for scanning to function. If Semgrep is missing, the mode effectively behaves as off.

Critical Interaction with auto_run

A vital safety check exists in interpreter/terminal_interface/start_terminal_interface.py (lines 420‑424): if both safe_mode and auto_run are enabled, the system forces auto_run to False. This prevents the dangerous scenario where code is automatically executed without prior human review or security scanning.

The Semgrep Scanning Engine

The actual security analysis occurs in interpreter/core/utils/scan_code.py (lines 30‑48). The scan_code() function:

  1. Writes the code snippet to a temporary file
  2. Executes semgrep --config auto against it
  3. Captures the output and exit code

If Semgrep returns a non-zero exit code (indicating findings), the user sees an error summary (lines 53‑56). In auto mode, successful scans print a "Code Scanner:" prefix to confirm the check occurred without findings.

LLM-Generated Safety Tags

Complementary to safe_mode, some LLM outputs may contain XML tags like <safe>, <warning>, or <unsafe>. The streaming handlers in interpreter/core/llm/run_tool_calling_llm.py and run_function_calling_llm.py (lines 11‑18) strip these tags and emit review messages. While independent of the Semgrep-based safe_mode, these tags provide additional metadata that downstream tools can use for risk assessment.

Security Trade-offs and Considerations

Attack Surface Reduction

Without safe mode (off), a compromised or malicious LLM could generate code to install backdoors, exfiltrate environment variables, or destroy data. Enabling ask or auto forces a static analysis step that catches dangerous patterns—such as usage of os.system, subprocess calls, or suspicious network activity—before execution.

Dependence on Semgrep Rules

The effectiveness of safe mode hinges entirely on the quality of Semgrep's auto-generated rule set (--config auto). While this provides sensible defaults for common vulnerabilities, it may miss novel attack vectors or zero-day exploits. Additionally, false positives could desensitize users to warnings, potentially leading to automated dismissal of legitimate alerts.

Performance and Usability Impact

  • ask mode: Adds friction by requiring a prompt for every code snippet, which may interrupt development flow during trusted, repetitive tasks.
  • auto mode: Introduces execution delays proportional to code snippet size, as Semgrep runs as a subprocess for every block.

Dependency Requirements

Safe mode requires the semgrep package to be installed separately. If missing, the interpreter warns the user at startup (line 62‑64 in terminal_interface.py) but continues operation effectively in off mode, creating a silent security gap if users ignore the warning.

Practical Configuration Examples

Enable safe mode programmatically or via CLI:


# Enable interactive scanning (ask mode)

from interpreter import interpreter
interpreter.safe_mode = "ask"

# Enable automatic scanning (auto mode)

interpreter.safe_mode = "auto"

# Disable all protection (high risk)

interpreter.safe_mode = "off"

Command-line usage:


# Start with automatic safe mode

interpreter --safe=auto

# Or use ask mode

interpreter --safe=ask

Example session flow in ask mode:

> print("Hello World")

  print("Hello World")

Would you like to scan this code? (y/n) y

Code Scanner: 0 findings

Would you like to run this code? (y/n)

Summary

  • The safe_mode parameter is Open Interpreter's primary defense against malicious code execution, with three distinct levels: off, ask, and auto.
  • Never use off in production or with untrusted LLMs, as it permits arbitrary code execution without inspection.
  • auto mode provides the strongest security guarantee by enforcing Semgrep scans on every code block, but requires the semgrep package and adds execution latency.
  • Safe mode automatically disables auto_run (as enforced in start_terminal_interface.py lines 420‑424) to prevent unsupervised execution.
  • The security mechanism relies on Semgrep's rule database, which offers good coverage of common vulnerabilities but is not infallible against sophisticated or novel attacks.

Frequently Asked Questions

What happens if I enable safe_mode but don't have Semgrep installed?

If Semgrep is not installed, Open Interpreter prints a warning at startup stating that safe mode requires semgrep, then continues execution as if safe_mode were set to off. You must install Semgrep separately (pip install semgrep) for the security scanning to function.

Does safe_mode prevent all malicious code execution?

No. Safe mode uses Semgrep with the --config auto rule set, which catches common dangerous patterns but cannot guarantee detection of all malicious code, zero-day exploits, or obfuscated attacks. It significantly reduces risk but should be combined with other security practices like running in sandboxed environments.

Why does enabling safe_mode disable auto_run?

As implemented in interpreter/terminal_interface/start_terminal_interface.py (lines 420‑424), enabling safe mode forces auto_run to False to prevent the dangerous combination of automatic execution with automatic scanning. This ensures a human review step always occurs between the security scan and code execution.

Can I use safe_mode with the OpenAI API or other remote models?

Yes. The safe_mode parameter functions at the interpreter level, independent of which LLM provider you use. Whether using local models or APIs like OpenAI, the code generated by the model is still passed through the same Semgrep scanning pipeline before execution when safe mode is active.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →