+ Local api server is designed to allow local access to Geoffrey without a token + Uses a unix domain socket, allowing permissions to be handled by the OS + Started work on a tool to exploit this, geoffrey-cli