Local and custom models ask before every command and outbound call
In NeuralVault 2.0 a model you run yourself or reach through a custom endpoint is not trusted by default, so it asks before every shell command and every outbound call, and you can mark one trusted.
Last checked against the app on · View as Markdown
Steps
- Choose a local model (Ollama, the local gateway) or a custom endpoint in Chat. A notice appears under the message box: "NeuralVault cannot check where this model came from. It will ask you before every command it runs and every outbound call it makes."
- The reason: a model you downloaded could be a poisoned copy that behaves normally until a rare trigger, then asks for a command that sends your files somewhere. NeuralVault cannot verify where a model came from and cannot tell a poisoned one from a good one. So instead of trying to judge the model, it limits what an unvouched model can do without a person saying yes.
- For such a model these always ask on a card: shell commands, web fetches and searches, integration calls, GitHub writes and git push. Each card has no "do not ask again" choice, a standing allow rule does not answer it, and a run with nobody there never runs it.
- Even if you approve every card, such a model gets at most three outbound calls in one turn. The fourth is refused. Every outbound call that goes ahead leaves one audit row with the tool, the host, roughly how many bytes, and who approved it.
- Models from the hosted providers in the model list, and NeuralVault Managed, are trusted by default. For those the mode and the safety guard decide each call as usual.
- If you know where a local model came from, press "I know where this model came from, mark it trusted" on the notice. Marking it only stops these extra cards. The mode and the safety guard still apply. "Dismiss" hides the notice but the model still asks.
- To undo it, open Settings, then Intelligence, then API keys, find the "Trusted models" group, and press "Stop trusting" beside the model. The group also shows whether the selected model is trusted.
How to tell it worked
With a local model selected, the first shell command or web fetch it asks for shows a card with no option to remember the answer.
If it does not work
- It keeps asking, even for a command you approved a minute ago.
- That is the point for an untrusted model: answers are never remembered. Mark the model trusted if you know its source, or choose a hosted model.
- It was refused after three web calls in one turn.
- That is the cap on outbound calls for an untrusted model. Ask in a new message, or mark the model trusted.
- The model itself is not found or gives an empty list.
- That is a different problem. See the guide on local model problems.