Skip to content

docs(security): point to the shared security page and keep MAX specifics - #387

Merged
leemour merged 1 commit into
mainfrom
docs/security-shared
Oct 4, 2026
Merged

leemour merged 1 commit into
mainfrom
docs/security-shared

Conversation

@leemour

@leemour leemour commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Task

The tg and max security pages repeated the same shared design. The owner asked for one shared security page on wirecat.dev, with each tool page keeping only its own details and linking to it. The owner also asked for a private way to report a vulnerability.

Why

  • One home per fact: the store, the send guard and agent boundaries are one implementation in cli-messaging.
  • No repository had a SECURITY.md.

What

The shared page lands in leemour/cli-docs on branch docs/architecture. Its links show up on the site with the next max release.

Testing

  • pnpm lint, pnpm typecheck, pnpm test (1371 passed), pnpm docs:check, pnpm parity:check: all pass.

🤖 Generated with Claude Code

The generic parts — the local store, the send guard, agent boundaries,
other people's text, what others on the machine see, personal use under
GDPR — now live on the shared page at wirecat.dev/ru/docs/security,
which tg and max both link. This page keeps what only MAX has: the
token and MAX_TOKEN, the bot token, max serve's checks, the bot guard
keys, MAX's endpoints and client imitation, MAX's terms, browser login,
the unofficial protocol and what to do when a token leaks.

Adds SECURITY.md with the private reporting channels, and corrects
docs/dev/ARCHITECTURE.md §1 and §17: max now plugs into cli-messaging
through maxMessenger and maxAdapter, and MCP tools follow permissions.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@leemour
leemour merged commit 1c7d919 into main Oct 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant