This Signal bridge is mostly disclosed, but it lets remote Signal messages wake and steer an agent while the advertised permission and triage controls are largely advisory rather than enforced.
Install only for a dedicated Signal bot/account and treat every incoming Signal message as untrusted input. Before enabling cron or the wake hook, protect the signal-cli data directory, wake token, permissions file, and conversation logs; require local confirmation for commands, installs, file/config changes, and permission changes requested over Signal; and define retention or disable plaintext logging if conversations may contain sensitive data.