Skip to content

Name the relay threat; spell out labels that read as codes - #29

Merged
fylorn merged 1 commit into
mainfrom
copy/relay-threat
Sep 30, 2026
Merged

fylorn merged 1 commit into
mainfrom
copy/relay-threat

Conversation

@fylorn

@fylorn fylorn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor
  • Security card, hero, meta, home Lite section and Lite docs overview: a relay sees every request and can rewrite every answer; outbound redaction keeps keys from it and tool-call inspection cuts off dangerous tool calls it slips in (download-and-run, sending out env vars or credential files, reading private keys, startup items and scheduled jobs — the built-in rules in tw-guard). Still stated as capabilities: the protections start in Observe.
  • Home pills (MIT → MIT open source, platforms with parentheses), comparison-table status cells as sentences, architecture control-channel lines as platform: channel.

🤖 Generated with Claude Code

A relay sees every request and can rewrite every answer, including slipping in
a tool call that the client then runs on the machine. The Lite page, the home
page and the Lite docs now say so, and say what tool-call inspection cuts off.
Also spells out labels that read as codes: the home page's Lite pills, the
comparison table's status cells and the architecture's control-channel lines.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@fylorn
fylorn merged commit 1b27925 into main Sep 30, 2026
1 check passed
@fylorn
fylorn deleted the copy/relay-threat branch September 30, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant