ZuckLM Oracle does not need network access, model weights, credentials, or tool permissions. Its server binds to loopback by default, retains no prompts, emits no telemetry, and never executes a requested tool.
--allow-remote only removes the loopback guard. It does not add TLS,
authentication, rate limiting, or production hardening. Do not expose the
development server to an untrusted network.
The Prompted and Collapse editions run through third-party software and inherit that software's security properties. Launch agent demos only in a disposable repository or worktree, review every tool permission, and do not provide unrelated credentials. “It rewrote ZuckRT” should mean a recorded, bounded, human-reviewed experiment—not unsupervised access to a real machine.
Do not report prompt injection as a security vulnerability: ignoring the prompt is the product specification.