Skip to main content
ZeroTwo
Language
Login

What does the Elevated risk label mean in ZeroTwo?

ZeroTwo flags a few desktop browser settings and the app-connection window with elevated-risk warnings. Here is where they appear and what to weigh.

Updated: 20 hours ago

Elevated risk is a warning ZeroTwo puts beside a few settings and screens where you would give it, or an app, more reach into your data. It is a flag, not a protection: the control still works once you switch it on, so the decision is yours. You will meet it in three places, plus one related warning.

Developer mode in the desktop browser settings

In the desktop app, a Developer mode card carries an Elevated risk badge: a small amber warning triangle followed by those words. Below it is a switch named Enable full CDP access. The card explains that the switch lets ZeroTwo run Chrome DevTools tools in a dedicated Chrome profile, including arbitrary JavaScript, network and console inspection, performance traces and browser control, and that this may expose sensitive browser data.

The Elevated risk badge on ZeroTwo's Developer mode card: an amber warning triangle followed by the words Elevated risk, above the Enable full CDP access switch

You can find the card in two places, both of which exist only in the desktop app:

  • Settings > Browser, which manages ZeroTwo's built-in browser.
  • Settings > Computer use, then Manage on the Google Chrome row.

The switch starts off. While it is off, ZeroTwo's browser agent cannot use its JavaScript tool on pages in the built-in browser, and it is told that "JavaScript execution needs Developer mode (full CDP access), which is turned off."

Always allow for website approval

Open Settings > Computer use and choose Manage beside Google Chrome. Under Permissions, the Approval row lets you choose whether ZeroTwo asks before it opens websites.

ChoiceWhat it does
Always askAsk before opening websites.
Always allowOpen websites without asking. An orange shield icon and the line "This setting has elevated risks for your data." appear under this choice.

ZeroTwo starts with Approval set to Always allow, so if you would rather be asked first, change it to Always ask. The History, Downloads and Uploads rows beneath it offer Always allow, Always ask and Never, without that extra warning line. Further down, an Advanced switch named Allow all browser actions skips per-action approval and carries its own note that it can put your data at risk.

Connecting an app

When you connect an app that signs in through its own sign-in page, ZeroTwo first opens a window titled "Use app name in ZeroTwo" with a few notices. One is headed Apps may introduce elevated risk. It says that although ZeroTwo is built to protect your data, an attacker could try to go through ZeroTwo to your data in the app, or through the app to your data in ZeroTwo.

The next notice, Data shared with this app, says that by adding the app you let it access the basic information typically shared when you visit a website, such as your IP address and approximate location, plus a summary of your recent context and intent within ZeroTwo.

The same window has a switch, Reference memories and chats, which controls whether ZeroTwo may use relevant chats and memories when it shares data with that app. When you reconnect an app you already connected, or add a second account for it, ZeroTwo can skip this window and go straight to the app's sign-in, because you have already seen it. For the full flow, see Connect your apps to ZeroTwo with connectors and Control what ZeroTwo can do in a connected app.

A related warning: Full access

In the desktop app, a new Code or Work chat shows a permission picker in the message box, beside the + button. Its menu asks "How should ZeroTwo actions be approved?" and by default offers Ask for approval, Approve for me and Full access. Full access, described as unrestricted access to the internet and any file on your computer, is the only choice tinted orange. It does not carry the words Elevated risk; the orange tint is its only warning.

Deciding what to turn on

  • Leave Enable full CDP access off unless you need ZeroTwo to inspect or script a web page.
  • Switch Approval to Always ask if ZeroTwo will visit sites you do not control.
  • Connect only apps you trust, and use Reference memories and chats only where you want that context to travel with your requests.

Need more help? Search with the help chat, email us or ask in the ZeroTwo community on Discord.

Help chat

Signed in to ZeroTwo? Open Help, then Support, in the app to send us a message.

Related articles

Was this article helpful?

Log in to message us in the app.

Log in

ZeroTwo help chat

Get help from ZeroTwo

This chat only searches the articles here. It isn’t a person or an AI, and sends nothing. To reach ZeroTwo, email reed@zerotwo.ai or join the ZeroTwo Discord.